Setting Up the Issuance of CRLs
606
Netscape Certificate Management System Administrator’s Guide • February 2003
In the adjoining text field, type the interval, in minutes, at which the Certificate
Manager should publish CRLs. For example, if you want the server to publish
CRLs every day, you should type 1440 in this field.
with a skew of.
If you configure the Certificate Manager to update the CRL at a
specific frequency, the server by default adds a 5 second skew to the next
update time to allow time to create the CRL and publish it. For example, if you
configure the server to update the CRL every 20 minutes, and if the CRL is
updated at 16:00:00, the CRL will be updated again at 16:19:55. You can change
the skew by editing the default value, which is specified in seconds.
In the CRL Cache section, specify whether to enable CRL caching:
Enable CRL cache.
Select to enable the cache. Note, if the cache is disabled,
you cannot create delta CRLs. For more information about the cache, see “How
CRLs Work,” on page 601.
Cache update interval.
Specifies the period of time when the cache is written
to file. Set to
0
to have the cache written to file every time a certificate is
revoked.
Include expired certificates.
Select if you want the server to include revoked
certificates that have expired in the CRL. If this is enabled, information about
revoked certificates will remain in the CRL after the certificate expires. If you
do not enable, information about revoked certificates is removed when the
certificate expires.
CA certificates only.
Select to include only CA certificates in the CRL; deselect
to include all certificates. Selecting this option will create an Authority
Revocation List (ARL) listing only revoked CA certificates.
Allow extensions.
Select if you want to allow extensions in the CRL. If you
enable this option, the server generates and publishes CRLs conforming to
X.509 version 2 standard. If you disable this option, the server generates and
publishes CRLs conforming to X.509 version 1 standard. By default, the server
publishes version 1 CRLs. If you enable this option, be sure to set the required
CRL extensions as described in “Setting CRL Extensions” on page 607.
Note: Extensions must be turned on in order to create delta CRLs.
Revocation list signing algorithm.
Select the algorithm the server should use
to sign the CRL. If the Certificate Manager’s signing key type is RSA, select
MD2
with RSA
,
MD5 with RSA
, or
SHA-1 with RSA
. If the Certificate Manager’s
signing key type is DSA, select
SHA-1 with DSA
.
4.
To save your changes, click Save.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...