Setting up the OCSP Responder
163
1. Go to the CA's end-entities page. For example:
https://server.example.com:9443/ca/ee/ca/
2. Find the CA signing certificate.
3. Look for the Authority Info Access extension in the certificate, and note the
Location URIName
value, such as
http://server.example.com:9080/ca/ocsp
.
4. Update the enrollment profiles to enable the Authority Information Access extension, and set the
Location
parameter to the Certificate Manager's URI. For information on editing the certificate
profiles, see
Section 13.3, “Setting up Certificate Profiles”
.
5. Restart the CA instance.
/etc/init.d/
instance_ID
restart
To disable the Certificate Manager's internal OCSP service, edit the CA's
CS.cfg
file and change the
value of the
ca.ocsp
parameter to
false
.
ca.ocsp=false
6.7. Setting up the OCSP Responder
If a CA within the security domain is selected when the Online Certificate Status Manager is
configured, there is no extra step required to configure the OCSP service. The CA's CRL publishing
is set up automatically, and its signing certificate is automatically added and trusted in the Online
Certificate Status Manager's certificate database. However, if a non-security domain CA is selected,
then the OCSP service must be manually configured after the Online Certificate Status Manager is
configured.
NOTE
Not every CA within the security domain to which the OCSP Manager belongs is
automatically trusted by the OCSP Manager when it is configured. Every CA in the
certificate chain of the CA configured in the CA panel is trusted automatically by the
OCSP Manager. Other CAs within the security domain but not in the certificate chain must
be trusted manually.
To set up the Online Certificate Status Manager for a Certificate Manager outside the security domain,
do the following:
1. Configure the CRLs for every CA that will publish to an OCSP responder. See
Chapter 14,
Revocation and CRLs
for details.
2. Enable publishing, set up a publisher, and set publishing rules in every CA that the OCSP
service will handle. See
Chapter 15, Publishing
for details. This is not necessary if the Certificate
Managers publish to an LDAP directory and the Online Certificated Status Manager is set up to
read from that directory.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...