Testing The Ocsp Cloned-Master Connection; Cloned-Master Ocsp Responder Conversion; Converting A Master Ocsp Responder Into A Cloned Ocsp Responder - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

Testing the OCSP Cloned-Master Connection

Follow these steps to test whether your cloned-master OCSP setup is complete and
functional.
Setup OCSP Publishing in the master CA so that the CRL will be published to the
1.
master Online Certificate Status Manager.
Once the CRL is successfully published, check both the master and cloned Online
2.
Certificate Status Manager's List Certificate Authorities menu option in the agent
interfaces. The output should be identical.
Use the OCSPClient tool to submit OCSP requests to the master and the cloned Online
3.
Certificate Status Manager. The tool should receive identical OCSP responses from
both Managers.

Cloned-Master OCSP Responder Conversion

In the event that the user needs to convert an existing cloned OCSP Responder into a new
master OCSP Responder (e. g. - a catastrophic failure of the existing master OCSP
Responder), one needs to first convert the master existing offline master OCSP Responder
into a clone followed by converting one of the current existing online cloned OCSP
Responders into the new online master OCSP Responder.
The difference between a master OCSP Responder and a cloned OCSP Responder is the
following:
Cloned OCSP Responders contain a unique configuration parameter
Converting a Master OCSP Responder into a Cloned
OCSP Responder
Since only one master OCSP Responder can exist for a CS installation, the offline master
must first be converted into a cloned OCSP Responder since one of the cloned OCSP
Responders will become the new master OCSP Responder (see Converting a Cloned OCSP
Responder into a Master OCSP Responder).
First, ensure that the existing master OCSP Responder is not running:
Go to the existing master OCSP Responder configuration directory at the command
1.
line:
cd <serverRoot>/cert-<masterID>/config
Cloning the Online Certificate Status Manager
Chapter 17
Configuring CS for High Availability
667

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents