Policy; Crls; Publishing; Notifications - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Features

Policy

The policy feature of CS allows you to set policies about certificate issuance, renewal, and
revocation. You set policies that either define what is possible, for example the possible
values of for the expiration date, and extensions that are used in a particular type of
certificate. A set of prebuilt policies is available for you to enable and configure. You can
create additional Policy plug-in modules using the CS SDK. See Chapter 12, "Policies" for
complete details.

CRLs

CS is capable of creating certificate revocation lists. This configurable framework allows
you to define issuing points so a CRL can be created for each issuing point defined. You
can issue CRLs for each type of certificate you issue, or for a specific subset of a type of
certificate you issue. You can also configure the extensions used in the CRLs, and set up the
frequency and intervals that CRLs are published. Delta CRLs can also be created for any
issuing point that is defined.
The Certificate Manager can issue X.509 v1 or v2 CRLs. A CRL can be automatically
updated whenever a certificate is revoked or at specified intervals. See Chapter 15,
"Revocation and CRLs" for complete details.

Publishing

The publishing feature allows you to publish certificates to files and an LDAP directory,
and CRLs to files, LDAP directory, and an OCSP responder. The publishing framework
provides a robust set of tools that allow you to publish to all three methods, and enables you
to create rules that allow you to define a finer granularity of which types of certificates or
CRLs are published where. You can enable and configure the default publishing modules,
or you can create additional publishing plug-in modules using the CS SDK. See Chapter 16,
"Publishing" for complete details.

Notifications

Notifications is a feature that allows you to set up automated messages when a particular
event occurs, such as when a certificate is issued or revoked. The notification framework
comes with default modules that you can enable and configure. You can create additional
notification plug-in modules using the CS SDK. See Chapter 13, "Automated
Notifications" for complete details.
34
Red Hat Certificate System Administrator's Guide • September 2005

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents