Enabling Automatic Revocation Checking for Agent Certificates
185
4. Edit the following parameters:
•
revocationChecking.bufferSize
. Sets the total number of last-checked certificates the
server should maintain in its cache. For example, if the buffer size is 2, the server retains the
last two certificates checked in its cache. By default, the server caches the last 50 certificates.
•
revocationChecking.
subsystem
. Gives the name of the Certificate System instance.
subsystem
indicates whether the subsystem is a Certificate Manager (
ca
). Do not change the
default values.
•
revocationChecking.enabled
. Sets revocation checking.
true
enables checking;
false
disables checking. By default, the feature is enabled.
•
revocationChecking.unknownStateInterval
. Sets how frequently the server checks
the revocation status. The default interval is 0 seconds.
•
revocationChecking.validityInterval
. Sets how long the cached certificates are
considered valid. Be judicious when choosing the interval. For example, if the validity period
is 60 seconds, the server discards the certificates in its cache every minute and attempts to
retrieve them from their source. The Certificate Manager uses its internal database to retrieve
and verify the revocation status of the certificates. The default validity period is 120 seconds (2
minutes).
5. Start the Certificate System instance.
service
instance_ID
start
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...