What’s an OCSP-Compliant PKI Setup?
690
Netscape Certificate Management System Installation and Setup Guide • October 2001
What’s an OCSP-Compliant PKI Setup?
Certificate Management System supports the Online Certificate Status Protocol
(OCSP) as defined in the PKIX standard RFC 2560 (see
http://www.ietf.org/rfc/rfc2560.txt
). The OCSP protocol enables
OCSP-compliant applications to determine the state of a certificate, including the
revocation status, without having to directly check a CRL published by a CA to the
validation authority. The validation authority, which is also called an OCSP
responder, does the checking for the application.
An OCSP-compliant PKI setup generally includes the following, which work
together to verify the revocation status of a certificate:
•
A CA, which issues and revokes certificates, and periodically publishes the
CRL to the OCSP responder.
•
An OCSP responder, which maintains the CRL it receives periodically from the
CA and, when queried by an OCSP-compliant client about the status of a
certificate, sends a digitally signed response.
•
OCSP-compliant applications, which, when trying to validate a certificate,
query the appropriate OCSP responder (using the OCSP protocol) for the
status of the certificate. The applications determine the location of the OCSP
responder by using the Authority Information Access Extension in the
certificate being validated. (Certificate Management System enables you to add
this extension to certificates. For details, see “Configuring Policy Rules for a
Subsystem” on page 589.)
The revocation-status-verification process has two parts:
1.
When a certificate’s status needs to be verified, the OCSP client (an
OCSP-compliant application) sends a request to the OCSP responder for
verification and waits for a response from the responder.
The OCSP request that the client submits generally contains all the information
required by the responder to identify the certificate whose status it needs to
determine.
(Consider this process is similar to a cashier scanning your credit card and
waiting for a response from the credit-card processing unit. The scanning unit
sends identifying information, such as the credit card number, its type, validity
period, and so on.)
2.
Upon receipt of the request, the OCSP responder determines if the request
contains all the information required by the responder to process it.
Содержание NETSCAPE MANAGEMENT SYSTEM 4.5
Страница 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Страница 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 80: ...Standards Summary 80 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 328: ...Password Quality Checker 328 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 434: ...Deleting a Privileged User 434 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 794: ...Managing Log Modules 794 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Страница 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 834: ...Object Identifiers 834 Netscape Certificate Management System Installation and Setup Guide October 2001...
Страница 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...