Administration Guide
x
13.8.1. Basic Constraints Extension Constraint ......................................................... 316
13.8.2. Extended Key Usage Extension Constraint .................................................... 317
13.8.3. Extension Constraint .................................................................................... 317
13.8.4. Key Constraint ............................................................................................. 317
13.8.5. Key Usage Extension Constraint ................................................................... 317
13.8.6. No Constraint .............................................................................................. 319
13.8.7. Netscape Certificate Type Extension Constraint ............................................. 319
13.8.8. Signing Algorithm Constraint ......................................................................... 319
13.8.9. Subject Name Constraint .............................................................................. 319
13.8.10. Unique Subject Name Constraint ................................................................ 320
13.8.11. Validity Constraint ....................................................................................... 320
14. Revocation and CRLs 321
14.1. Revocation ............................................................................................................. 321
14.1.1. SSL Client Authenticated Revocation ............................................................ 321
14.1.2. Certificate Revocation Forms ........................................................................ 321
14.2. CMC Revocation .................................................................................................... 322
14.2.1. Setting up CMC Revocation ......................................................................... 322
14.2.2. Testing CMC Revoke ................................................................................... 323
14.3. About CRLs ............................................................................................................ 323
14.3.1. Reasons for Revoking a Certificate ............................................................... 324
14.3.2. Publishing CRLs .......................................................................................... 325
14.3.3. CRL Issuing Points ...................................................................................... 325
14.3.4. Delta CRLs .................................................................................................. 325
14.3.5. How CRLs Work .......................................................................................... 325
14.4. Issuing CRLs .......................................................................................................... 326
14.4.1. Configuring Issuing Points ............................................................................ 328
14.4.2. Configuring CRLs for Each Issuing Point ....................................................... 329
14.4.3. Setting CRL Extensions ................................................................................ 333
14.5. Setting Full and Delta CRL Schedules ..................................................................... 334
14.5.1. Configuring Extended Updated Intervals for CRLs in the Console .................... 335
14.5.2. Configuring Extended Updated Intervals for CRLs in CS.cfg ............................ 336
15. Publishing 337
15.1. About Publishing ..................................................................................................... 337
15.1.1. About Publishers .......................................................................................... 337
15.1.2. About Mappers ............................................................................................ 337
15.1.3. About Rules ................................................................................................. 338
15.1.4. Publishing to Files ........................................................................................ 338
15.1.5. LDAP Publishing .......................................................................................... 338
15.1.6. OCSP Publishing ......................................................................................... 339
15.1.7. How Publishing Works ................................................................................. 339
15.2. Setting up Publishing .............................................................................................. 340
15.3. Configuring Publishers ............................................................................................ 341
15.3.1. Configuring Publishers for Publishing to a File ............................................... 341
15.3.2. Configuring Publishers for Publishing to OCSP .............................................. 343
15.3.3. Configuring Publishers for LDAP Publishing ................................................... 345
15.4. Configuring Mappers ............................................................................................... 346
15.5. Rules ..................................................................................................................... 350
15.5.1. Modifying Publishing Rules for Certificates and CRLs ..................................... 351
15.5.2. Predicates Used in Publishing Rules ............................................................. 355
15.6. Enabling Publishing ................................................................................................ 355
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...