![Red Hat CERTIFICATE SYSTEM 8 - AGENTS GUIDE Agents Manual Download Page 69](http://html.mh-extra.com/html/red-hat/certificate-system-8-agents-guide/certificate-system-8-agents-guide_agents-manual_1427434069.webp)
Chapter 5.
59
CA: Publishing to a Directory
A Red Hat Directory Server installation is required for the Certificate System subsystems to be
installed; this directory instance maintains user information and certificate and key information. The
Certificate System can be configured to publish certificates and CRLs to that directory, or other
LDAP directories, for other applications to access. Certificate information published to the publishing
directory must be periodically updated as certificates are issued and revoked. Updates are usually
published automatically but may also be published manually.
This chapter describes the procedures for updating an LDAP directory with the current status of
certificates. Only a Certificate Manager agent can manage publishing certificates and CRLs to the
directory.
5.1. Automatically Updating the Directory
Once the Certificate System administrator has configured the Certificate System to publish to
the publishing Directory Server, any changes to certificate information in Certificate System are
automatically updated in the publishing directory at specific times.
• The first time the Certificate System is started, it publishes the Certificate Manager's CA certificate
to the LDAP publishing directory.
• When the Certificate System issues a new certificate, the certificate is published to the LDAP
publishing directory.
• When the Certificate System revokes a certificate, the certificate is removed from the publishing
directory.
• When the CRL is created or updated, the list is published to the LDAP publishing directory.
For more information on configuring the Certificate System to publish to the Directory Server, see the
Certificate System Administrator's Guide
.
5.2. Manually Updating the Directory
The LDAP publishing directory usually does not need certificate data updated manually because
most updates are automatic. However, it may be necessary to update the LDAP publishing directory
manually in the following situations:
• The publishing Directory Server is down for a period of time and unable to receive changes from the
Certificate System.
• Expired certificates need to be removed from the publishing directory since certificates are not
automatically removed from the publishing directory when they expire.
NOTE
Any client using a certificate is responsible for determining its validity by checking the
expiration date against the client's current date information.
To update the LDAP publishing directory with changes manually: