Setting CRL Extensions
333
7. Click
Save
.
8. Extensions are allowed for this issuing point and can be configured. See
Section 14.4.3, “Setting
CRL Extensions”
for details.
14.4.3. Setting CRL Extensions
NOTE
Extensions only need configured for an issuing point if the
Allow extensions for CRLs v2
checkbox is selected for that issuing point.
When the issuing point is created, three extensions are automatically enabled:
CRLReason
,
InvalidityDate
, and
CRLNumber
. Other extensions are available but are disabled by default.
These can be enabled and modified. For more information about the available CRL extensions, see
Section A.5, “Standard X.509 v3 CRL Extensions”
.
To configure CRL extensions, do the following:
1. Open the CA Console.
pkiconsole https://
hostname:SSLport
/ca
2. In the navigation tree, select
Certificate Manager
, and then select
CRL Issuing Points
.
3. Select the issuing point name below the
Issuing Points
entry, and select the
CRL Extension
entry below the issuing point.
The right pane shows the
CRL Extensions Management
tab, which lists configured extensions.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...