Configuring Extended Updated Intervals for CRLs in the Console
183
6.4.1. Configuring Extended Updated Intervals for CRLs in the
Console
1. Open the console.
pkiconsole https://server.example.com:9445/ca
2. In the
Configuration
tab, expand the
Certificate Manager
folder and the
CRL Issuing Points
subfolder.
3. Select the
MasterCRL
node.
4. Deselect the
Extend next update time in full CRLs
check box, which disables publishing a full
CRL every time a CRL is published. Then, set the new full CRL interval in the
Generate full CRL
every ... deltas
field.
5. Save the changes.
6.4.2. Configuring Extended Updated Intervals for CRLs in CS.cfg
Two parameters need to be configured for setting the full/delta CRL publishing interval in the
CS.cfg
file,
ca.crl.extendedNextUpdate
and
ca.crl.MasterCRL.updateSchema
.
1. Stop the CA server.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...