
Setting Up the OCSP Responder
176
Red Hat Certificate System Administrator’s Guide • September 2005
27.
Configuration Status.
This screen should indicate that your configuration has been
successful and that you need to create an agent for the Online Certificate Status
Manager.
Click Done to exit the Installation Wizard.
28.
You now need to create the first
agent
user for the Online Certificate Status Manager.
See “Agent Certificates,” on page 324 for details.
Setting Up the OCSP Responder
In order to properly set up the Online Certificate Status Manager, you must set up the
following:
1.
Configure every CA that will publish to the OCSP Responder to Publish CRLs. See
Chapter 15, “Revocation and CRLs” for complete details.
2.
Enable Publishing and set up a publisher and a publishing rule(s) to publish CRLs to
the Online Certificate Status Manager in every CA that the OCSP will handle. See
Chapter 16, “Publishing” for complete details. (You do not need to do this if the
Certificate Manager publishes to an LDAP directory and the Online Certificated Status
Manager is set up to read from that LDAP publishing directory.)
3.
You must configure your policies or certificate profiles for every CA that will publish
to the OCSP Responder to include the Authority Information Access extension
pointing to the location at which the Certificate Manager listens for OCSP service
requests (identified as the
AuthInfoAccessExt
instance in the policy framework.)
in
certificates that are issued. This extension is necessary to identify the OSCP service. If
you installed the Certificate Manager with the OSCP service on, this extension is
created with the correct information for the OSCP service. If you chose not to
configure the OSCP service, you will have to create this policy and configure it for this
service.
If you installed the Certificate Manager’s with its OCSP service feature disabled, a
default policy rule (named
AuthInfoAccessExt
) is created, but it may not have the
correct attributes for adding the Authority Information Access extension to certificates.
See Chapter 12, “Policies” for details on configuring policies, see
“AuthInfoAccessExt,” on page 489 for specific information on this policy module.
4.
Configure the OCSP Responder. See “Configuring the Online Certificate Status
Manager,” on page 177. Pay close attention to configuring the following:
❍
Configure the Revocation Info stores. See “Configure the Revocation Info Stores,”
on page 182.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...