Publishing Certificates And Crls; About Publishing - Red Hat CERTIFICATE SYSTEM 8.0 - ADMINISTRATION Admin Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION:
Table of Contents

Advertisement

Chapter 8.

Publishing Certificates and CRLs

Red Hat Certificate System includes a customizable publishing framework for the Certificate Manager,
enabling certificate authorities to publish certificates, certificate revocation lists (CRLs), and other
certificate-related objects to any of the supported repositories: an LDAP-compliant directory, a flat file,
and an online validation authority. This chapter explains how to configure a Certificate Manager to
publish certificates and CRLs to a file, to a directory, and to the Online Certificate Status Manager.
The general process to configure publishing is as follows:
1. Configure publishing to a file, LDAP directory, or OCSP responder.
There can be a single publisher or multiple publishers, depending on how many locations will
be used. The locations can be split by certificates and CRLs or narrower definitions, such as
certificate type. Rules determine which type to publish and to what location by being associated
with the publisher.
2. Set rules to determine what certificates are published to the locations. Any rule which a certificate
or CRL matches is activated, so the same certificate can be published to a file and to an LDAP
directory by matching a file-based rule and matching a directory-based rule.
Rules can be set for each object type: CA certificates, CRLs, user certificates, and cross-pair
certificates. Disable all rules that will not be used.
3. Configure CRLs. CRLs must be configured before they can be published. See
Revoking Certificates and Issuing
4. Enable publishing after setting up publishers, mappers, and rules. Once publishing is enabled,
the server starts publishing immediately. If the publishers, mappers, and rules are not completely
configured, publishing may not work correctly or at all.

8.1. About Publishing

The Certificate System is capable of publishing certificates to a file or an LDAP directory and of
publishing CRLs to a file, an LDAP directory, or to an OCSP responder.
For additional flexibility, specific types of certificates or CRLs can be published to a single format or
all three. For example, CA certificates can be published only to a directory and not to a file, and user
certificates can be published to both a file and a directory.
NOTE
An OCSP responder only provides information about CRLs; certificates are not published
to an OCSP responder.
Different publishing locations can be set for certificates files and CRL files, as well as different
publishing locations for different types of certificates files or different types of CRL files.
Similarly, different types of certificates and different types of CRLs can be published to different places
in a directory. For example, certificates for users from the West Coast division of a company can be
published in one branch of the directory, while certificates for users in the East Coast division can be
published to another branch in the directory.
CRLs.
Chapter 6,
203

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?

Table of Contents