Configuring Crls For Each Issuing Point - Red Hat CERTIFICATE SYSTEM 7.2 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.2 - ADMINISTRATION:
Table of Contents

Advertisement

extensions. All the CRLs created appear on the Update Revocation List page of the agent services
pages.

13.4.2. Configuring CRLs for Each Issuing Point

Information, such as the generation interval, the CRL version, CRL extensions, and the signing
algorithm, can all be configured for the CRLs for the issuing point. The CRLs must be configured for
each issuing point.
1. Open the CA Console.
pkiconsole https://hostname:SSLport/ca
2. In the navigation tree, select Certificate Manager, and then select CRL Issuing Points.
3. Select the issuing point name below the Issuing Points entry.
4. Configure how and how often the CRLs are updated by supplying information in the Update tab
for the issuing point. This tab has two sections, Update Schema and Update Frequency.
• The Update Schema section has the following options:
• Enable CRL generation. This checkbox sets whether CRLs are generated for that issuing
point.
• Generate full CRL every # delta(s). This field sets how frequently CRLs are created in
relation to the number of changes.
• Extend next update time in full CRLs. This adds the nextUpdate field to the published
CRLs, which indicates the date by which the next CRL will be issued.
Configuring CRLs for Each Issuing Point
295

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents