Chapter 8. Online Certificate Status Manager: Verifying Certificate Status
96
Figure 8.1. OCSP List Certificate Authorities Page
8.2. Identifying a CA to the Online Certificate Status
Manager
The Online Certificate Status Manager can be configured to receive CRLs from multiple Certificate
Managers. Before configuring a Certificate Manager to publish CRLs to the OCSP, first identify the
Certificate Manager to the Online Certificate Status Manager by storing the Certificate Manager's CA
signing certificate in the internal database of the Online Certificate Status Manager.
To store the Certificate Manager's CA signing certificate in the internal database of the Online
Certificate Status Manager:
1. Open the Certificate Manager's end-entities page.
http
s
://server.example.com:
9444/ca/ee/ca
2. Select the
Retrieval
tab, and, in the left frame, click
List Certificates
.
3. When the page opens, click
Find
.
4. Locate the Certificate Manager's CA signing certificate by looking at the subject name of the
certificate. Typically, the CA signing certificate is the first certificate the Certificate Manager issues.