Administration Guide
x
13.8.1. Basic Constraints Extension Constraint ......................................................... 316
13.8.2. Extended Key Usage Extension Constraint .................................................... 317
13.8.3. Extension Constraint .................................................................................... 317
13.8.4. Key Constraint ............................................................................................. 317
13.8.5. Key Usage Extension Constraint ................................................................... 317
13.8.6. No Constraint .............................................................................................. 319
13.8.7. Netscape Certificate Type Extension Constraint ............................................. 319
13.8.8. Signing Algorithm Constraint ......................................................................... 319
13.8.9. Subject Name Constraint .............................................................................. 319
13.8.10. Unique Subject Name Constraint ................................................................ 320
13.8.11. Validity Constraint ....................................................................................... 320
14. Revocation and CRLs 321
14.1. Revocation ............................................................................................................. 321
14.1.1. SSL Client Authenticated Revocation ............................................................ 321
14.1.2. Certificate Revocation Forms ........................................................................ 321
14.2. CMC Revocation .................................................................................................... 322
14.2.1. Setting up CMC Revocation ......................................................................... 322
14.2.2. Testing CMC Revoke ................................................................................... 323
14.3. About CRLs ............................................................................................................ 323
14.3.1. Reasons for Revoking a Certificate ............................................................... 324
14.3.2. Publishing CRLs .......................................................................................... 325
14.3.3. CRL Issuing Points ...................................................................................... 325
14.3.4. Delta CRLs .................................................................................................. 325
14.3.5. How CRLs Work .......................................................................................... 325
14.4. Issuing CRLs .......................................................................................................... 326
14.4.1. Configuring Issuing Points ............................................................................ 328
14.4.2. Configuring CRLs for Each Issuing Point ....................................................... 329
14.4.3. Setting CRL Extensions ................................................................................ 333
14.5. Setting Full and Delta CRL Schedules ..................................................................... 334
14.5.1. Configuring Extended Updated Intervals for CRLs in the Console .................... 335
14.5.2. Configuring Extended Updated Intervals for CRLs in CS.cfg ............................ 336
15. Publishing 337
15.1. About Publishing ..................................................................................................... 337
15.1.1. About Publishers .......................................................................................... 337
15.1.2. About Mappers ............................................................................................ 337
15.1.3. About Rules ................................................................................................. 338
15.1.4. Publishing to Files ........................................................................................ 338
15.1.5. LDAP Publishing .......................................................................................... 338
15.1.6. OCSP Publishing ......................................................................................... 339
15.1.7. How Publishing Works ................................................................................. 339
15.2. Setting up Publishing .............................................................................................. 340
15.3. Configuring Publishers ............................................................................................ 341
15.3.1. Configuring Publishers for Publishing to a File ............................................... 341
15.3.2. Configuring Publishers for Publishing to OCSP .............................................. 343
15.3.3. Configuring Publishers for LDAP Publishing ................................................... 345
15.4. Configuring Mappers ............................................................................................... 346
15.5. Rules ..................................................................................................................... 350
15.5.1. Modifying Publishing Rules for Certificates and CRLs ..................................... 351
15.5.2. Predicates Used in Publishing Rules ............................................................. 355
15.6. Enabling Publishing ................................................................................................ 355
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...