Agent Certificates
342
Netscape Certificate Management System Administrator’s Guide • February 2003
The configuration files of both Certificate Manager and Registration Manager
include parameters that enable you to specify whether the server should do the
revocation checking and if it should, at what interval. Note that the
revocation-status verification works for only those agent certificates that have been
issued by the Certificate Manager (and not by any third-party CAs).
To configure a Certificate Manager or Registration Manager to verify the
revocation status of its agents’ certificates:
1.
Stop the CMS instance; see “Starting, Stopping, and Restarting CMS Instances”
on page 254.
2.
Go to the following directory:
<server_root>/cert-<instance_id>/config
3.
Open the
CMS.cfg
file in a text editor.
4.
Edit the following parameters as appropriate.
NOTE
The CMS configuration file (
CMS.cfg
) includes a parameter named
jss.ocspcheck.enable
, which enables you to specify whether a
CMS manager should use Online Certificate Status Protocol (OCSP)
to verify the revocation status of the certificate it receives as a part
of SSL client or server authentication (from clients or servers it
makes connections with). If you change the value of this parameter
to
true
, the CMS manager reads the Authority Information Access
extension in the certificate and verifies the revocation status of the
certificate from the OCSP responder specified in the extension.
revocationChecking.bufferSize
Specifies the total number of last-checked
certificates the server should maintain in its
cache. For example, if you configure the
buffer size to be 2, the server retains the last
two certificates it checked in its cache. By
default, the server caches the last 50
certificates.
revocationChecking.<subsystem>
Specifies the name of the CMS instance.
<subsystem>
indicates whether the
subsystem is a Certificate Manager (
ca
) or
Registration Manager (
ra
). You must not
change the default values.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...