About OCSP Services
Chapter
5
OCSP Responder
167
•
A responder that holds a specially marked certificate issued to it directly by the
CA that revokes the certificates and publishes the CRL. Possession of this
certificate by a responder indicates that the CA has authorized the responder to
issue OCSP responses for certificates revoked by the CA. Such a responder is
called a CA-designated responder or a CA-authorized responder.
CMS has a built-in OCSP responder and allows you to request OCSP
responder certificates. The end-entity interface of both Registration Manager
and Certificate Manager includes a form that allows you to manually request a
certificate for the OCSP responder. The default enrollment form includes all
the attributes (for example,
HTTP_PARAMS.certType==ocspResponder
) that
identify the certificate as an OCSP responder certificate. The required policies
extensions, such as OCSPNoCheck, ExtendedKeyUsageExt with RuleID, and
OCSPSigning, can be added to the certificate when the certificate request is
subjected to policy checking; see “Configuring Policy Rules for a Subsystem”
on page 489.
For more information about the certificates associated with OCSP, see “SSL Server
Key Pair and Certificate,” on page 171.
OCSP Responses
The OCSP response that the client receives indicates the current status of the
certificate as determined by the OCSP responder. The response could be any of the
following:
•
Good or Verified—specifying a positive response to the status inquiry. At a
minimum, this positive response indicates that the certificate has not been
revoked, but it does not necessarily mean that the certificate was ever issued or
that the time at which the response was produced is within the certificate’s
validity interval. Response extensions may be used to convey additional
information on assertions made by the responder regarding the status of the
certificate such as positive statement about issuance, validity, etc.
•
Revoked—specifying that the certificate has been revoked, either permanently
or temporarily.
•
Unknown—specifying that the OCSP responder doesn’t know about the
certificate whose status is being requested by the client.
Based on the status, the client decides whether to validate the certificate.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...