Online Certificate Status Manager Deployment Considerations
170
Netscape Certificate Management System Administrator’s Guide • June 2003
2.
Set up CRLs. You need to configure the Certificate Manager to issue CRLs. See
Chapter 14, “Revocation and CRLs” for details on configuring CRLs.
3.
You must configure your policies or certificate profiles to include the Authority
Information Access extension pointing to the location at which the Certificate
Manager listens for OCSP service requests (identified as the
AuthInfoAccessExt
instance in the policy framework.)
in certificates that are
issued. This extension is necessary to identify the OSCP service. If you installed
the Certificate Manager with the OSCP service on, this extension is created
with the correct information for the OSCP service in the policy framework, and
is not enabled by default. If you chose not to configure the OSCP service, you
will have to create this policy and configure it for this service.
If you installed the Certificate Manager’s with its OCSP service feature
disabled, a default policy rule (named
AuthInfoAccessExt
) is created, but it
may not have the correct attributes for adding the Authority Information
Access extension to certificates.
See Chapter 11, “Policies” for details on configuring policies, see
“AuthInfoAccessExt,” on page 508 for specific information on this policy
module.
4.
Make sure the OCSP SSL signing certificate is from a CA that is trusted by the
Certificate Manager. See “OCSP Certificates,” on page 189 for more
information.
Online Certificate Status Manager Deployment
Considerations
This section describes the decisions you make during installation that will apply to
your initial configuration of the subsystem.
Online Certificate Status Manager Certificates
When you install the Online Certificate Status Manager, the keys for the OCSP
signing certificate and SSL server certificate are created and a certificate request is
made for the signing certificate and the SSL server certificate.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...