Predicates Used in Publishing Rules
355
15.5.2. Predicates Used in Publishing Rules
Table 15.3, “Predicate Expressions”
lists the predicates that can be used to identify CRL issuing points
and delta CRLs and certificate profiles.
Predicate Type
Predicate
CRL Issuing Point
issuingPointId==
Issuing_Point_Instance_ID
&& isDeltaCRl==[true|false]
To publish only the master CRL, set
isDeltaCRl==false
. To publish only the delta
CRL, set
isDeltaCRl==true
. To publish both,
set a rule for the master CRL and another rule for
the delta CRL.
Certificate Profile
profileId==
profile_name
To publish certificates based on the profile used
to issue them, set
profileId==
to a profile
name, such as
caServerCert
.
Table 15.3. Predicate Expressions
15.6. Enabling Publishing
Publishing can be enabled for only files, only LDAP, or both. Publishing should be enabled after
setting up publishers, rules, and mappers. Once enabled, the server will attempt to begin publishing.
If publishing was not configured correctly before being enabled, publishing may exhibit undesirable
behavior or may fail.
Enable publishing by doing the following:
1. Log into the Certificate Manager Console.
pkiconsole https://server.example.com:9443/ca
2. In the
Configuration
tab, select
Certificate Manager
from the navigation tree on the left. Select
Publishing
.
The right pane shows the details for publishing to an LDAP-compliant directory.
3. To enable publishing to a file only, select
Enable Publishing
.
4. To enable LDAP publishing, select both
Enable Publishing
and
Enable Default LDAP
Connection
.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...