Chapter 14. Revocation and CRLs
336
5. Save the changes.
14.5.2. Configuring Extended Updated Intervals for CRLs in CS.cfg
Two parameters need to be configured for setting the full/delta CRL publishing interval in the
CS.cfg
file,
ca.crl.extendedNextUpdate
and
ca.crl.MasterCRL.updateSchema
.
1. Stop the CA server.
/etc/init.d/rhpki-ca stop
2. Open the CA configuration directory.
cd /var/lib/
subsystem_name
/conf
3. Edit the
CS.cfg
file, and add two lines to set the extended updated interval:
ca.crl.extendedNextUpdate=false
ca.crl.MasterCRL.updateSchema=3
The default interval is 1, meaning a full CRL is published every time a CRL is published. The
updateSchema
interval can be set to any integer.
4. Restart the CA server.
/etc/init.d/rhpki-ca start
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...