Red Hat CERTIFICATE SYSTEM 7.3 - AGENT GUIDE Manual page 68

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - AGENT GUIDE:
Table of Contents

Advertisement

Chapter 6. CA: Publishing to a Directory
NOTE
Any client using a certificate is responsible for determining its validity by checking the
expiration date against the client's current date information.
To update the LDAP publishing directory with changes manually, do the following:
1. Open the CM agent services page.
2. Click Update Directory Server.
3. Select Skip certificates already marked as updated to ignore certificates in the internal database
that have already been published or removed, in the case of revoked certificates.
In some circumstances, updating the LDAP publishing directory can take considerable time. During
this period, any changes made through the Certificate System such as issuing or revoking certific-
ates may not be included in the update. If certificates have been issued or revoked during that time,
the publishing directory must be updated again to reflect those changes. Use the Skip certificates
already marked as updated option the second time to update only certificates that been issued,
revoked, or expired while the previous update was running.
4. Select the type of update to perform.
• To publish the latest CRL, select Update certificate revocation list to the publishing
directory.
• To update information on valid certificates to the publishing directory, select Update valid certi-
ficates to the directory.
To update a range of certificates, such as only the most recently issued certificates, specify the
range of the serial numbers of those certificates.
• To remove expired certificates from the publishing directory, select Remove expired certificates
from the directory.
To remove a range of certificates instead of all expired certificates, specify the range of the serial
numbers of those certificates.
• To remove revoked certificates from the publishing directory, select Remove revoked certific-
ates from the directory.
If you want to remove a range of certificates instead of all revoked certificates, specify the range
of the serial numbers of those certificates.
62

Advertisement

Table of Contents
loading

Table of Contents