Configuring The Directory For Ldap Publishing - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Configuring the Directory for LDAP Publishing

c.
Revoke the Certificate.
7.
Check the File for the CRL
8.
Check whether the server generated the DER-encoded file containing the CRL.
9.
To check whether the server published the CRL as a binary blob to the specified
directory, go to the directory you specified for the server to publish CRLs. You should
find a file with its name in the
<this_update>
This Update
configuration.
Convert the DER-encoded CRL to its base 64-encoded format using the Binary to
10.
ASCII tool. See step 5 for directions.
Convert the base 64-encoded CRL to a human-readable form using the Pretty Print
11.
CRL tool. See step 6 for directions.
Repeat this test for each kind of certificate or CRL you are issuing. Remember to check
12.
for the published certificate or CRL in all the places you set up publishing for the
certificate or CRL.
Configuring the Directory for LDAP Publishing
Before you can use a directory for publishing of certificates and CRLs, you must configure
that directory to work correctly with your publishing system. The following sections detail
what you will need to configure:
Schema
Entry for the CA
632
Red Hat Certificate System Administrator's Guide • September 2005
For example, if the base-64 encoded certificate is in
C:\certificates\cert-1234.txt
the certificate to be displayed on your screen, the command would look like this:
PrettyPrintCert C:\certificates\cert-1234.txt
When the conversion is complete, you should see the certificate you issued in
human-readable form.
Compare the output with the certificate you issued; be sure to check the serial
number in the certificate with the one used in the filename.
If everything matches, the Certificate Manager is configured correctly to publish
certificates to files.
specifies the value derived from the time-dependent variable named
of the CRL contained in the file. If you don't see the file, check your
and you want the human-readable form of
crl-<this_update>.der
format, where

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents