
Setting CRL Extensions
299
7. Click
Save
.
8. Extensions are allowed for this issuing point and can be configured. See
Section 13.4.3, “Setting
CRL Extensions”
for details.
13.4.3. Setting CRL Extensions
NOTE
Extensions only need configured for an issuing point if the
Allow extensions for CRLs v2
checkbox is selected for that issuing point.
When the issuing point is created, three extensions are automatically enabled:
CRLReason
,
InvalidityDate
, and
CRLNumber
. Other extensions are available but are disabled by default.
These can be enabled and modified. For more information about the available CRL extensions, see
Section A.5, “Standard X.509 v3 CRL Extensions”
.
To configure CRL extensions, do the following:
1. Open the CA Console.
pkiconsole https://
hostname:SSLport
/ca
2. In the navigation tree, select
Certificate Manager
, and then select
CRL Issuing Points
.
3. Select the issuing point name below the
Issuing Points
entry, and select the
CRL Extension
entry below the issuing point.
The right pane shows the
CRL Extensions Management
tab, which lists configured extensions.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...