
Testing Your OCSP Setup
Chapter 5
OCSP Responder
185
4.
Download the certificate to the browser or client.
5.
Make sure the CA is trusted by the browser or client.
6.
Check the Status of Certificate Manager’s OCSP Service (internal OCSP service).
Go to the agent services interface for the Certificate Manager and then go to the OCSP
Services page.
The Certificate Manager’s Agent services interface contains a form that enables you to
check the Certificate Manager’s OCSP-service status, such as how many request its
received and so on. Click OCSP Services in the left frame in the agent services
interface.
7.
Check the Status of Online Certificate Status Manager (stand-alone OCSP service).
Go to the agent services interface for the Online Certificate Status Manager and then go
to the List Certificate Authorities page found in the left frame.
The resulting form should show information about the Certificate Manager (CA) you
configured to publish CRls to the Online Certificate Status Manager. The page also
summarizes the Online Certificate Status Manager’s activity since it was last started.
8.
Revoke the certificate
9.
Verify the certificate in the browser or client. Once verified, you should see that the
certificate has been revoked.
10.
Check the Certificate Manager’s OCSP Service Status (internal OCSP) again
Check the Certificate Manager’s OCSP-service status again to verify that these things
happened:
❍
The browser sent an OCSP query to the Certificate Manager (this response was
initiated when you clicked the View button).
❍
The Certificate Manager sent an OCSP response to the browser.
❍
The browser used that response to validate the certificate and informed you of its
status (that the certificate could not be verified).
11.
Check the Online Certificate Status Manager Status (stand-along OCSP service) Again
Check the Online Certificate Status Manager status again to verify that these things
happened:
❍
The Certificate Manager published the CRL (the revoked certificate) to the Online
Certificate Status Manager.
❍
The browser sent an OCSP response to the Online Certificate Status Manager (this
response was initiated when you clicked the View button).
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...