Setting Up Jobs
The jobs feature that allows you to send automated jobs is disabled after installation. The
Online Certificate Status Manager contains the framework for jobs, but does not contain
any prebuilt jobs. You can build jobs using the CS SDK. For detailed information on setting
up publishing, see Chapter 14, "Automated Jobs."
Identifying the CA to the OCSP Responder
Before you configure a Certificate Manager to publish CRLs to the Online Certificate
Status Manager, you must identify the Certificate Manager to the Online Certificate Status
Manager. You do this by storing the Certificate Manager's CA signing certificate in the
internal database of the Online Certificate Status Manager. The Certificate Manager signs
CRLs with the key pair associated with this certificate; the Online Certificate Status
Manager verifies the signature against the stored certificate.
Get the Certificate Manager's CA signing certificate in base 64 encoded format. You
1.
should be able to get this from the end-entity interface of the CA that issued the
certificate, or the end-entity interface of the Certificate Manager if the certificate is
self-signed.
Go to the Online Certificate Status Manager's Agent interface. The URL is:
2.
h
ttps://<hostname>:<port>
The Online Certificate Status Manager Agent Services interface appears.
In the left frame, click Add Certificate Authority.
3.
In the form, paste the encoded CA signing certificate inside the text area labeled "Base
4.
64 encoded certificate (including the header and footer)."
Click Add.
5.
The certificate is added to the internal database of the Online Certificate Status
Manager.
To verify that the certificate is added successfully, in the left frame, click List
6.
Certificate Authorities.
The resulting form should show information about the Certificate Manager (CA) you
just added. Note the values assigned to the "This Update," "Next Update," and
"Requests Served Since Startup" fields. All three fields should show a value of zero
(0).
Configuring the Online Certificate Status Manager
.
Chapter 5
OCSP Responder
181
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?