Chapter 7. Using the Online Certificate Status Protocol Responder
190
•
baseDN.
The DN to start searching for the CRL. For example,
O=example.com
.
•
refreshInSec.
How often the connection is refreshed. The default is 86400 seconds (daily).
•
caCertAttr.
Leave the default value,
cACertificate;binary
, as it is. It is the attribute to
which the Certificate Manager publishes its CA signing certificate.
•
crlAttr.
Leave the default value,
certificateRevocationList;binary
, as it is. It is the
attribute to which the Certificate Manager publishes CRLs.
•
notFoundAsGood.
Sets the OCSP service to return an OCSP response of GOOD if the
certificate in question cannot be found in any of the CRLs. If this is not selected, the response is
UNKNOWN, which, when encountered by a client, results in an error message.
•
includeNextUpdate.
The Online Certificate Status Manager can include the timestamp of the
next CRL update time.
7.2.3. Testing the OCSP Service Setup
Test whether the Certificate Manager can service OCSP requests properly by doing the following:
1. Turn on revocation checking in the browser or client.
2. Request a certificate from the CA that has been enabled for OCSP services.
3. Approve the request.
4. Download the certificate to the browser or client.
5. Make sure the CA is trusted by the browser or client.
6. Check the status of Certificate Manager's internal OCSP service.
Open the CA agent services page, and select the
OCSP Services
link.
7. Test the independent Online Certificate Status Manager subsystem.
Open the Online Certificate Status Manager agent services page, and click the
List Certificate
Authorities
link.
The page should show information about the Certificate Manager configured to publish CRLs to
the Online Certificate Status Manager. The page also summarizes the Online Certificate Status
Manager's activity since it was last started.
8. Revoke the certificate.
9. Verify the certificate in the browser or client. The server should return that the certificate has been
revoked.
10. Check the Certificate Manager's OCSP-service status again to verify that these things happened:
• The browser sent an OCSP query to the Certificate Manager.
• The Certificate Manager sent an OCSP response to the browser.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...