Ocsp Responses; Cs Ocsp Services - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

CS has a built-in OCSP responder and allows you to request OCSP responder
certificates. The end-entity interface of both Registration Manager and Certificate
Manager includes a form that allows you to manually request a certificate for the OCSP
responder. The default enrollment form includes all the attributes (for example,
HTTP_PARAMS.certType==ocspResponder
OCSP responder certificate. The required policies extensions, such as OCSPNoCheck,
ExtendedKeyUsageExt with RuleID, and OCSPSigning, can be added to the certificate
when the certificate request is subjected to policy checking; see "Configuring Policy
Rules for a Subsystem" on page 471.
For more information about the certificates associated with OCSP, see "SSL Server Key
Pair and Certificate," on page 162.

OCSP Responses

The OCSP response that the client receives indicates the current status of the certificate as
determined by the OCSP responder. The response could be any of the following:
Good or Verified—specifying a positive response to the status inquiry. At a minimum,
this positive response indicates that the certificate has not been revoked, but it does not
necessarily mean that the certificate was ever issued or that the time at which the
response was produced is within the certificate's validity interval. Response extensions
may be used to convey additional information on assertions made by the responder
regarding the status of the certificate such as positive statement about issuance,
validity, etc.
Revoked—specifying that the certificate has been revoked, either permanently or
temporarily.
Unknown—specifying that the OCSP responder doesn't know about the certificate
whose status is being requested by the client.
Based on the status, the client decides whether to validate the certificate.

CS OCSP Services

To aid you in the process of setting up a OCSP-compliant PKI setup, CS provides two
options:
The OCSP-service feature built into the Certificate Manager
The Online Certificate Status Manager
) that identify the certificate as an
Chapter 5
OCSP Responder
CS OCSP Services
159

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents