![Red Hat CERTIFICATE 7.1 ADMINISTRATOR Скачать руководство пользователя страница 125](http://html.mh-extra.com/html/red-hat/certificate-7-1-administrator/certificate-7-1-administrator_administrators-manual_1427416125.webp)
Federal Bridge CA
Chapter 3
Certificate Manager
125
Revocation
An end entity can request that their own certificate is revoked.
When an end entity makes the request, they are asked to present their certificate. If they
have the certificate and the key materials, the request is processed and sent to the Certificate
Manager and the certificate is revoked. Once approved, the signed request is sent to the
Certificate Manager and the certificate is revoked. The Certificate Manager marks the
certificate as revoked in its database, and adds it to any CRLs that are applicable.
An agent can revoke any certificate issued by the Certificate Manager. They do this by
searching for the certificate in the agent services interface and then marking it revoked.
Once a certificate is revoked, it is marked revoked in the database, and in the publishing
directory if the Certificate is set up for publishing.
If you enabled and configured the internal OCSP service, the service determines the status
of certificates by looking them up in the internal database and reporting on the status of the
certificate.
You can set up an automated notifications that send an email message to the end entity
when their certificate is revoked. You set this up by enabling and configuring the Certificate
Revoked notification message, and customizing the email template associated with this
notification.
Federal Bridge CA
CS supports Federal Bridge Certificate Authority (FBCA) by providing the capability to
issue, import, and publish cross-pair CA certificates.
With cross-pair certificates, one CA signs and issues a cross-pair certificate to a second CA,
and the second CA signs and issues a cross-pair certificate to the first CA. Both CAs then
store and or publish both certificates as a
crossCertificatePair
.
This may be done when you want to honor certificates issued by a CA that does not chain
up to your root CA. By establishing a trust between your CA and another CA through a
cross-pair CA certificate, you can download this cross-pair certificate using it to trust the
certificates that are issued by the other CA.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...