Publishing Crls To The Online Certificate Status Manager - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

If authentication is based on SSL client authentication, the directory
administrator needs to create an entry in the directory's
The
certmap.conf
directory entry that specifies write permission to the appropriate portion of the
directory tree.
If you intend to publish certificates to the directory, the directory administrator
needs to have an entry for each user to whom you intend to issue a certificate,
and the directory schema must include a location to which the certificate
should be published. If you want to publish the CA certificate or CRL, you will
also need an entry for the CA.
If you intend to use SSL authentication, both the directory and the Certificate
Manager must be configured appropriately for SSL. For detailed information on
LDAP publishing, see Chapter 19, "Setting Up LDAP Publishing."
Publishing CRLs to the Online Certificate Status
Manager
Certificate Management System supports the Online Certificate Status Protocol
(OCSP) as defined in the PKIX standard RFC 2560 (see
http://www.ietf.org/rfc/rfc2560.txt
OCSP-compliant applications to determine the state of a certificate, including the
revocation status, without having to directly check a CRL published by a CA to the
validation authority. The validation authority, which is also called an OCSP
responder, does the checking for the application. For more information, see "What's
an OCSP-Compliant PKI Setup?" on page 690.
To aid you in the process of setting up a OCSP-compliant PKI setup, Certificate
Management System provides two options:
Use the OCSP-service feature built into the Certificate Manager
Use the CMS OCSP responder, named Online Certificate Status Manager
Read section "How to Get an OCSP Responder?" on page 692 to decide which
method is suitable for your PKI setup.
entry maps the DN in the subsystem's client certificate to a
). The OCSP protocol enables
Publishing Decisions
certmap.conf
Chapter 4
Planning Your Deployment
file.
179

Advertisement

Table of Contents
loading

Table of Contents