Publishing of Certificates to a Directory
608
Netscape Certificate Management System Installation and Setup Guide • October 2001
The publishing directory is updated at these times:
•
When the Certificate Manager starts up, it publishes its CA signing certificate to
the directory.
•
When the Certificate Manager issues a new certificate (the request may
originate from Registration Managers that’re connected to the Certificate
Manager), it stores a copy of the certificate in its internal database and then
publishes the certificate to the configured directory.
•
When the Certificate Manager revokes a certificate (the request may originate
from Registration Managers that’re connected to the Certificate Manager), it
marks the copy of the certificate in its internal database as revoked and then
unpublishes or removes the revoked certificate from the configured directory.
•
When a certificate expires, the Certificate Manager can remove that certificate
from the configured directory. Note that the server doesn’t do this
automatically. You need to configure the server to run the appropriate job. For
details, see “Configuring a Subsystem to Run Automated Jobs” on page 565.
•
When the certificate revocation list is created or updated (either through the
CMS window or through the certificate-revocation feature provided in the
agent or end-entity interface), the Certificate Manager publishes that list to the
configured directory.
Table 19-1 summarizes the above-listed actions of the Certificate Manager. The
table also indicates how the Certificate Manager populates an LDAP directory, if
configured for publishing. Note that certificates (and CRLs) are published as
DER-encoded binary blobs.
Table 19-1
Details of objects published by the Certificate Manager
Object
Action and Timing
LDAP entry
LDAP attribute
End-entity
certificate
Publishing occurs when a certificate
is issued or renewed
End-entity’s
entry
userCertificate;binary
Unpublishing (removal) occurs
when a certificate is revoked or
expired
End-entity’s
entry
userCertificate;binary
CA certificate
Publishing occurs when the
Certificate Manager is started
CA’s entry
caCertificate;binary
CRL (full)
Publishing (replacement) occurs
when a new CRL is generated
CA’s entry
certificateRevocation
List;binary
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...