Configuring Certificate Manager to Publish to Files
676
Netscape Certificate Management System Installation and Setup Guide • October 2001
In the adjoining text field, type the interval, in minutes, at which the Certificate
Manager should publish CRLs. For example, if you want the server to publish
CRLs every day, you should type 1440 in this field.
with a skew of.
If you configure the Certificate Manager to update the CRL
automatically every time period, the server by default adds a 5 second skew to
the next update time to allow time to create the CRL and publish it. For
example, if you configure the server to update the CRL every 20 minutes, and
if the CRL is updated at 16:00:00, the CRL will be updated again at 16:19:55.
You can change the skew by editing the default value, which is specified in
seconds.
3.
In the CRL Cache section, specify whether to enable CRL caching:
Enable cache.
Check this box to enable CRL caching. Leave the box unchecked
if you don’t want the server to maintain a cache.
Update interval.
If you enabled caching, type the interval for updating the
cache.
4.
In the CRL Format section, specify the format for publishing the CRL:
Include expired certificates.
Check this box if you want the server to include
revoked certificates that have expired in the CRL.
Allow extensions.
Check this box if you want to allow extensions in the CRL. If
you enable this option, the server generates and publishes CRLs conforming to
X.509 version 2 standard. If you disable this option, the server generates and
publishes CRLs conforming to X.509 version 1 standard. By default, the server
publishes version 1 CRLs. If you enable this option, be sure to set the required
CRL extensions as described in “Step E. Set the CRL Extensions” on page 676.
Revocation list signing algorithm.
Select the algorithm the server should use
to sign the CRL. If the Certificate Manager’s signing key type is RSA, select
MD2
with RSA
,
MD5 with RSA
, or
SHA-1 with RSA
. If the Certificate Manager’s
signing key type is DSA, select
SHA-1 with DSA
.
5.
To save your changes, click Save.
The configuration is modified. If the changes you made require you to restart
the server, you are prompted accordingly. Don’t restart the server yet; you can
restart it after you’ve made all the required changes.
Step E. Set the CRL Extensions
Complete this step only if you configured the Certificate Manager to publish
version 2 CRLs in the previous step—that is, if you selected the “Allow extensions”
option in “Step D. Specify CRL Details” on page 674.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...