Configuring the Online Certificate Status Manager
Chapter
5
OCSP Responder
187
❍
Configure the Revocation Info stores. See “Configure the Revocation Info
Stores,” on page 193.
❍
Identify every Certificate Manager that will publish to the OCSP
Responder to the OCSP Responder. “Identifying the CA to the OCSP
Responder,” on page 191 for complete details.
❍
You may need to configure trust settings depending on who signed the
OCSP signing certificate. See “OCSP Certificates,” on page 189 for details.
5.
After configuring both the Certificate Manager and the Online Certificate
Status Manager, restart both.
6.
To verify that the CA is properly connected to the OCSP responder, see “Verify
Certificate Manager and Online Certificate Status Manager Connection,” on
page 192.
Configuring the Online Certificate Status
Manager
This section details the areas that you can configure for the Online Certificate
Status Manager and points you to specific information on configuring those sets of
features.
Adding Users
Once the Online Certificate Status Manager is installed, you need to add users and
assign them to the administrator, agent, and auditor roles. See Chapter 8,
“Authorization” for details on adding users and assigning them to groups.
Configuring Authorization
Each subsystem has a set of predefined groups that are assigned a default set of
privileges. You create users in the CMS database and then assign them to that
group to give them the privileges of that group. The privileges assigned to a role
are controlled by Access Control Instructions (ACIs) placed in Access Control Lists
(ACLs). ACLs define points that need specific authorization. Generally, each
defines a distinct set of functionality for the server. ACIs define what operations
can or cannot be performed by a user, group, or IP address for that particular ACL.
You can change the default ACIs set up in the ACLs to change the privileges. You
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...