![Netscape Certificate Management System 6.2 Скачать руководство пользователя страница 601](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697601.webp)
Setting Up the Issuance of CRLs
Chapter
14
Revocation and CRLs
601
Setting Up the Issuance of CRLs
The process of setting up the CRL feature includes the following tasks:
1.
The Certificate Manager will use its CA signing key to sign CRLs. If you want
to use a separate signing key pair for CRLs, you need to set up a CRL singing
key and change the Certificate Manager configuration to allow it to use this key
to sign CRLs. See “Getting a CRL Signing Key Pair and Certificate,” on page
114 for details on setting this up.
2.
Setting up CRL Issuing Points by enabling those you want to actually issue
CRLs. An issuing point is already set up and enabled for a Master CRL. You
can create any additional Issuing Points you want for the CRLs you want to
generate from those issuing points. See “Configuring Issuing Points,” on page
602 for complete details.
There are three possible issuing points you can create, select the correct options
when configuring the issuing point to define what the CRL will list:
Master CRL.
Containing the list of revoked certificates from the entire CA.
ARL.
Authority Revocation List containing only revoked CA certificates.
Master CRL and Expired Certificates.
Containing the list of revoked
certificates from the entire CA that also includes revoked certificates that have
expired.
3.
Configuring the CRLs for each issuing point by setting the parameters in the
Revocation List tab for that issuing point. See “Configuring CRLs for Each
Issuing Point,” on page 603 for complete details.
4.
Setting up the CRL extensions if you turned on extensions when you
configured the issuing point. See “Setting CRL Extensions,” on page 605 for
complete details.
5.
If you want to set up Delta CRLs for a particular issuing point, you need to
enable extensions for that issuing point, and enable and configure the
DeltaCRLIndicator
or
CRLNumber
.
6.
Setting up the
CRLDistributionPoint
extension in certificates you issue if you
want to include information about the issuing point where CRLs can be found
for that certificate. See Chapter 11, “Policies” for information about setting up
policies for constraints and certificate extensions; see
“CRLDistributionPointsExt,” on page 520 for specifics on setting up the
CRLDistributionPoint
extension in certificates you issue.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...