Red Hat CERTIFICATE SYSTEM 7.2 - ADMINISTRATION Administration Manual page 313

Hide thumbs Also See for CERTIFICATE SYSTEM 7.2 - ADMINISTRATION:
Table of Contents

Advertisement

Figure 13.1. Default CRL Issuing Point
Additional issuing points for the CRLs can be created. See
Points"
for details.
There are four types of CRLs the issuing points can create, depending on the options set when
configuring the issuing point to define what the CRL will list:
• Master CRL , which contains the list of revoked certificates from the entire CA.
• ARL , an Authority Revocation List containing only revoked CA certificates.
• CRL with expired certificates , which includes revoked certificates that have expired in the CRL.
• CRL from certificate profiles , which determines the revoked certificates to include based on the
profiles used to create the certificates originally.
3. Configure the CRLs for each issuing point. See
Issuing Point"
for details.
4. Set up the CRL extensions which are configured for the issuing point. See
CRL Extensions"
for details.
5. Set up the delta CRL for an issuing point by enabling extensions for that issuing point,
DeltaCRLIndicator or CRLNumber.
6. Set up the CRLDistributionPoint extension to include information about the issuing point.
7. Set up publishing CRLs to files, an LDAP directory, or an OCSP responder. See
Publishing
for details about setting up publishing.
Section 13.4.1, "Configuring Issuing
Section 13.4.2, "Configuring CRLs for Each
Issuing CRLs
Section 13.4.3, "Setting
Chapter 14,
293

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?

Table of Contents