Setting Up a Certificate Manager with OCSP Service
Chapter
5
OCSP Responder
171
service. The internal OCSP service checks certificate status by checking the internal
database of the Certificate Manager. The Online Certificate Status Manager checks
certificate status by checking CRLs provided by the Certificate Manger that it
stores in its own internal database.)
You can configure the Certificate Manager to generate and publish CRLs whenever
a certificate is revoked and at specified intervals, say every 20 minutes. Because the
purpose of setting up an OCSP responder is to facilitate real-time verification of
certificates, you should configure the Certificate Manager to generate and publish
the CRL to the Online Certificate Status Manager every time a certificate is
revoked—configuring the Certificate Manager to publish CRLs at specific intervals
would negate the very purpose for which it’s being done because the CRL the
Online Certificate Status Manager would look up during verification would always
be outdated. It’s important to note that if the CRL is large, the Certificate Manager
could take a considerable amount of time to publish the CRL.
As explained earlier, the Online Certificate Status Manager stores each Certificate
Manager’s CRL in its internal database and uses it as the default CRL store for
verifying certificates. You can also configure the Online Certificate Status Manager
to use the CRL published to an LDAP directory by a Certificate Manager. In this
case, the Certificate Manager does not have to update the CRLs the Online
Certificate Status Manager, it updates them to the LDAP directory which the
Online Certificate Status Manager is able to read. If you do so, the Online
Certificate Status Manager uses the CRL published to the LDAP directory, instead
of the CRL in its internal database.
For step-by-step instructions to set up an OCSP-compliant PKI setup using the
Online Certificate Status Manager, see “Installing an Online Certificate Status
Manager” on page 176.
Setting Up a Certificate Manager with OCSP
Service
The Certificate Manager has a built-in OCSP service feature that can be used by
OCSP-compliant clients to do real-time verification of certificates issued by the
Certificate Manager. This section explains how to setup an OCSP-compliant PKI
setup using the Certificate Manager’s OCSP-service feature.
You must have OCSP-compliant clients in order to be able to use the OCSP service.
1.
Make sure the OCSP service for the CA is enabled.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...