Configuring the Online Certificate Status Manager
Chapter
5
OCSP Responder
195
Configure the Revocation Info Stores
The Online Certificate Status Manager stores each Certificate Manager’s CRL in its
internal database and uses it as the default CRL store for verifying the revocation
status of certificates. You can also configure the Online Certificate Status Manager
to use the CRL published to an LDAP directory, instead of the CRL in its internal
database. For example, if you’ve configured Certificate Managers to publish CRLs
to LDAP directories (see Chapter 15, “Publishing”), you can configure the Online
Certificate Status Manager to use the CRLs published to these directories.
To configure the Online Certificate Status Manager to use the CRLs in its internal
database or an LDAP directory for verifying revocation status of certificate:
1.
Log in to the CMS window for the Online Certificate Status Manager (see
“Logging Into the CMS Console” on page 247).
2.
Select the Configuration tab.
3.
In the navigation tree, select Online Certificate Status Manager, and then select
Revocation Info Stores.
The right pane shows the two repositories the Online Certificate Status
Manager can use; by default, it uses the CRL in its internal database.
4.
Select the appropriate option:
❍
If you want to configure the Online Certificate Status Manager to use the
CRLs in its internal database, select
defStore
and click Edit/View.
❍
If you want to configure the Online Certificate Status Manager to use the
CRLs in one or more directories, first click Set Default to enable the
ldapStore
option, select
ldapStore
, and click Edit/View. (Clicking Set
Default toggles the selection between the two repositories.)
The Revocation Info Store Editor for the selected store appears.
5.
Fill in the appropriate values.
❍
If you selected
defStore
, fill in values as below:
notFoundAsGood.
A certificate’s status can typically be indicated by three
possible OCSP responses, namely GOOD, REVOKED, and UNKNOWN.
Select this option if you want the Online Certificate Status Manager to
return an OCSP response of GOOD if the certificate in question cannot be
found in any of the CRLs. If you deselect the option, the response will be
UNKNOWN, which when encountered by an OCSP-compliant client
results in an error message.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...