About Publishing
620
Netscape Certificate Management System Administrator’s Guide • February 2003
About Publishing to Files
The server can publish certificates and CRLs to flat files, which can then be
imported into any repository, for example, into a relational database. If you
configure the server to publish certificates and CRLs to flat files, it publishes them
to files as DER-encoded binary blobs.
•
For each certificate the server issues, it creates a file that contains the certificate
in its DER-encoded format. Each file is named
cert-<serial_number>.der
,
where
<serial_number>
specifies the serial number of the certificate
contained in the file. For example, the filename for a certificate with serial
number
1234
will be
cert-1234.der
.
•
Every time the server generates a CRL, it creates a file that contains the new
CRL in its DER-encoded format. Each file is named as
crl-<this_update>.der
, where
<this_update>
specifies the value derived
from the time-dependent variable named
This Update
of the CRL contained
in the file. For example, the filename for a CRL with
This Update: Friday
January 28 15:36:00 PST 2000
, will be
crl-949102696899.der
.
About LDAP Publishing
The ability of a server to publish certificates, CRLs, and other certificate-related
objects to a directory using the LDAP or LDAPS protocol is called LDAP publishing
and the directory to which it publishes is called the publishing directory.
•
For each certificate the server issues, it creates a blob that contains the
certificate in its DER-encoded format in the specified attribute of the user’s
entry. The certificate is published as a DER encoded binary blob.
•
Every time the server generates a CRL, it creates a blob that contains the new
CRL in its DER-encoded format in the specified attribute of the entry for the
CA.
The server can publish certificates and CRLs to an LDAP-compliant directory using
the LDAP protocol or LDAP over SSL (LDAPS) protocol, and applications can
retrieve the certificates and CRLs over HTTP. Support for retrieving certificates
and CRLs over HTTP enables some browsers, such as Netscape Communicator, to
automatically import the latest CRL from the directory that receives regular
updates from the server. The browser can then use the CRL to automatically check
all certificates to ensure that they have not been revoked.
For LDAP publishing to work, the user entry must be present in the LDAP
directory.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...