1. Get the Certificate Manager's base-64 CA signing certificate from the end-entities page of the CA.
2. Open the Online Certificate Status Manager agent page. The URL has the format
https://hostname:SSLport/ocsp/agent/ocsp.
3. In the left frame, click Add Certificate Authority.
4. In the form, paste the encoded CA signing certificate inside the text area labeled Base 64
encoded certificate (including the header and footer).
5. To verify that the certificate is added successfully, in the left frame, click List Certificate
Authorities.
The resulting form should show information about the new CA. The This Update, Next Update, and
Requests Served Since Startup fields should show a value of zero (0).
6.8.1. Verify Certificate Manager and Online Certificate Status
Manager Connection
When the Certificate Manager is restarted, it tries to connect to the Online Certificate Status Manager's
SSL port. To verify that the Certificate Manager did indeed communicate with the Online Certificate
Status Manager, check the This Update and Next Update fields, which should be updated with the
appropriate timestamps of the CA's last communication with the Online Certificate Status Manager.
The Requests Served Since Startup field should still show a value of zero (0) since no client has
tried to query the OCSP service for certificate revocation status.
6.8.2. Configure the Revocation Info Stores
The Online Certificate Status Manager stores each Certificate Manager's CRL in its internal database
and uses it as the CRL store for verifying the revocation status of certificates. The Online Certificate
Status Manager can be configured to use the CRL published to an LDAP directory, instead of the CRL
in its internal database.
To configure the Online Certificate Status Manager to use the CRLs in its internal database or an
LDAP directory for verifying revocation status of certificate, do the following:
1. Open the Online Certificate Status Manager Console.
pkiconsole https://hostname:SSLhost/ocsp
2. In the Configuration tab, select Online Certificate Status Manager, and then select Revocation
Info Stores.
The right pane shows the two repositories the Online Certificate Status Manager can use; by
default, it uses the CRL in its internal database.
3. Select the appropriate option:
• To use the CRLs in its internal database, select defStore, and click Edit/View.
• To use the CRLs in LDAP directories, click Set Default to enable the ldapStore option, select
ldapStore, and click Edit/View.
Verify Certificate Manager and Online Certificate Status Manager Connection
165
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?
Questions and answers