Configuring Remote CRLs
Configuring Remote CRLs
Configure automatic CRL downloads to help ensure that your CRLs are kept up to
date with minimal inconvenience. Enterprise Server supports CRL downloads over
HTTP, HTTP over SSL, LDAP, and LDAP over SSL. Once a CRL is downloaded,
Enterprise Server stores the information in memory. Enterprise Server will not
communicate with a client or server with a certificate listed on a CRL.
Enterprise Server provides two optional features you can enable for additional
confidence using the automated CRL download process:
•
Shut down server if CRL updates fail
Shuts down Enterprise Server when a CRL update fails for any reason. Before
Enterprise Server shuts down, an error message is written to the log for later
analysis.
•
Shut down server if CRLs are too old
Shuts down Enterprise Server if the age of a downloaded CRL exceeds the time
specified in its Next Update field. This condition indicates that the CRL may
not contain the most recent information available. To avoid the possibility of
users authenticating with compromised certificates that would have been
added to an up-to-date CRL, you can choose to have Enterprise Server shut
down automatically when a CRL is considered too old.
This check is performed when the CRL is downloaded. Therefore, an already
downloaded CRL can become older than its Next Update time in the interval
between updates and still be considered valid.
This feature does not apply to CRLs that do not have a Next Update field.
NOTE
Configuring Automatic/Remote CRL Downloads
To configure automatic/remote CRL downloads, perform the following steps:
Contact the CA for each CRL and get the following information:
1.
104
Netscape Enterprise Server Administrator's Guide • April 2002 (Draft)
For any CRL you use, be sure that the certificate for the
corresponding CA is installed in the certificate database for the
Enterprise Server instance. If you have enabled automatic/remote
CRL downloads, Enterprise Server will fail to start if the certificate
for the CA is not installed. See "Installing a Certificate," on page 97.
the URL for downloading updated CRLs
Need help?
Do you have a question about the NETSCAPE ENTREPRISE SERVER 6.1 - 04-2002 ADMINISTRATOR and is the answer not in the manual?