Chapter 6. Revoking Certificates and Issuing CRLs
180
6.3.3. Setting CRL Extensions
NOTE
Extensions only need configured for an issuing point if the
Allow extensions for CRLs v2
checkbox is selected for that issuing point.
When the issuing point is created, three extensions are automatically enabled:
CRLReason
,
InvalidityDate
, and
CRLNumber
. Other extensions are available but are disabled by default.
These can be enabled and modified. For more information about the available CRL extensions, see
Section B.4.2, “Standard X.509 v3 CRL Extensions Reference”
.
To configure CRL extensions, do the following:
1. Open the CA console.
pkiconsole https://server.example.com:9445/ca
2. In the navigation tree, select
Certificate Manager
, and then select
CRL Issuing Points
.
3. Select the issuing point name below the
Issuing Points
entry, and select the
CRL Extension
entry below the issuing point.
The right pane shows the
CRL Extensions Management
tab, which lists configured extensions.
Figure 6.5. CRL Extensions
4. To modify a rule, select it, and click
Edit/View
.
5. Most extensions have two options, enabling them and setting whether they are critical. Some
require more information. Supply all required values. See
Section B.4.2, “Standard X.509 v3 CRL
Extensions Reference”
for complete information about each extension and the parameters for
those extensions.
6. Click
OK
.
7. Click
Refresh
to see the updated status of all the rules.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...