About CRLs
598
Netscape Certificate Management System Administrator’s Guide • February 2003
.\CMCRevoke -d<dir to cert8.db, key3.db> -n<nickname>
-i<issuerName> -s<serialName> -m<reason to revoke> -c<comment>
For example, if the directory containing the agent certificate is
.netscape
, the
nickname of the certificate is
RegistartionManagerAgentCert
, and the serial
number of the certificate is
22
, the command would look like this:
.\CMCRevoke -d".\.netscape" -n"RegistartionManagerAgentCert"
-i"cn=agentAuthMgr" -s22 -m0 -c"test comment"
3.
Go to the end entity interface at the following URL:
https://localhost/ca/
4.
Select the Revocation Tab.
5.
Select the CMC Revoke link on the menu.
6.
Paste the output of step 2 into the text area
Remove
"-----BEGIN NEW CERTIFICATE REQUEST-----" and "----END NEW
CERTIFICATE REQUEST-----"
from the pasted content.
7.
Click Submit.
8.
Verify that the returned page confirms that the certificate 22 has been revoked.
About CRLs
Server and client applications that use public-key certificates as tokens of
identification need access to information about the validity of a certificate; because
one of the factors that determines the validity of a certificate is its revocation status,
these applications need to know whether the certificate being validated has been
revoked. In that regard, the CA has a responsibility to do the following:
•
Revoke the certificate if any of the certificate assertions becomes false.
•
Make the revoked certificate status available to parties or applications that
need to verify its validity status.
Whenever a certificate is revoked the Certificate Manager automatically updates
the status of the certificate in its internal database—it marks the copy of the
certificate in its internal database as revoked and removes the revoked certificate
from the publishing directory, if the Certificate Manager is configured to remove
the certificate from the database.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...