Setting Up The Ocsp Responder - Red Hat CERTIFICATE SYSTEM 7.2 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.2 - ADMINISTRATION:
Table of Contents

Advertisement

1. Go to the CA's end-entities page. For example:
https://server.example.com:9443/ca/ee/ca/
2. Find the CA signing certificate.
3. Look for the Authority Info Access extension in the certificate, and note the Location URIName
value, such as http://server.example.com:9080/ca/ocsp.
4. Update the enrollment profiles to enable the Authority Information Access extension, and set the
Location parameter to the Certificate Manager's URI. For information on editing the certificate
Section 12.3, "Setting up Certificate
profiles, see
5. Restart the CA instance.
/etc/init.d/instance_ID restart
To disable the Certificate Manager's internal OCSP service, edit the CA's CS.cfg file and change the
value of the ca.ocsp parameter to false.
ca.ocsp=false

5.7. Setting up the OCSP Responder

If a CA within the security domain is selected when the Online Certificate Status Manager is
configured, there is no extra step required to configure the OCSP service. The CA's CRL publishing
is set up automatically, and its signing certificate is automatically added and trusted in the Online
Certificate Status Manager's certificate database. However, if a non-security domain CA is selected,
then the OCSP service must be manually configured after the Online Certificate Status Manager is
configured.
NOTE
Not every CA within the security domain to which the OCSP Manager belongs is
automatically trusted by the OCSP Manager when it is configured. Every CA in the
certificate chain of the CA configured in the CA panel is trusted automatically by the
OCSP Manager. Other CAs within the security domain but not in the certificate chain must
be trusted manually.
To set up the Online Certificate Status Manager for a Certificate Manager outside the security domain,
do the following:
1. Configure the CRLs for every CA that will publish to an OCSP responder. See
Revocation and CRLs
2. Enable publishing, set up a publisher, and set publishing rules in every CA that the OCSP
service will handle. See
Managers publish to an LDAP directory and the Online Certificated Status Manager is set up to
read from that directory.
for details.
Chapter 14, Publishing
Setting up the OCSP Responder
Profiles".
for details. This is not necessary if the Certificate
Chapter 13,
131

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents