Polycom HDX 4000 Series Administrator's Manual page 210

Hide thumbs Also See for HDX 4000 Series:
Table of Contents

Advertisement

Polycom, Inc.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
some reason. Revoked certificates are considered invalid because they might
have been compromised in some way or improperly issued, or for other
similar reasons. The CA is responsible for maintaining the revocation status of
every certificate that it issues. The HDX system can check this revocation
status by using either of the following methods:
Certificate revocation lists (CRLs). A CRL is a list of certificates that have
been revoked by the CA. A CRL must be installed on the HDX system for
each CA whose certificate has been installed on the system.
The Online Certificate Status Protocol (OCSP). OCSP allows the HDX
system to contact an OCSP responder, which is a network server that
provides real-time certificate status through a query/response message
exchange.
You must configure the HDX system to use the revocation method most
appropriate for your environment.
To use CRLs:
Go to Admin Settings > Security > Revocation.
1
Configure these settings on the Revocation page.
2
Setting
Revocation Method
Allow Incomplete
Revocation Checks
Add CRL
The system fails any revocation check on a certificate if the system has an
expired CRL loaded for the issuing Certificate Authority (CA). To correct this,
you must delete and replace the expired CRL with an up-to-date version. You
can remove a CRL from the list by clicking Remove.
The HDX system does not support automatically downloading or updating CRLs.
The HDX system administrator is responsible for manually installing and updating
CRLs ahead of their expiration. It is extremely important that CRLs be kept up to
date prior to their expiration.
Description
Select the CRL method.
When this field is enabled, a certificate in the chain
is verified without a revocation status check if no
corresponding CRL for the issuing CA is installed.
The HDX system assumes that the lack of a CRL
means the certificate is not revoked. If a CRL is
installed, the system performs a revocation check
when validating the certificate.
1
Click Browse to search for and select a CRL.
2
Click Open to select the CRL.
3
Click Add to add the CRL to the HDX system.
Security
8–27

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents