Step B. Set The Crl Extensions - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

In the CRL Cache section, specify whether to enable CRL caching:
5.
Enable cache. Check this box to enable CRL caching. Leave the box unchecked
if you don't want the server to maintain a cache.
Update interval. If you enabled caching, type the interval for updating the
cache.
In the CRL Format section, specify the format for publishing the CRL:
6.
Include expired certificates. Check this box if you want the server to include
revoked certificates that have expired in the CRL.
Allow extensions. Check this box if you want to allow extensions in the CRL. If
you enable this option, the server generates and publishes CRLs conforming to
X.509 version 2 standard. If you disable this option, the server generates and
publishes CRLs conforming to X.509 version 1 standard. By default, the server
publishes version 1 CRLs. If you enable this option, be sure to set the required
CRL extensions as described in "Step B. Set the CRL Extensions" on page 715.
Revocation list signing algorithm. Select the algorithm the server should use
to sign the CRL. If the Certificate Manager's signing key type is RSA, select
,
with RSA
MD5 with RSA
signing key type is DSA, select
To save your changes, click Save.
7.
If the changes you made require you to restart the server, you are prompted
accordingly. However, don't restart the server yet; you can restart it after
you've made all the required changes.

Step B. Set the CRL Extensions

Complete this step only if you configured the Certificate Manager to publish
version 2 CRLs—that is, you selected the "Allow extensions" option in "Step A.
Specify CRL Format and Publishing Interval" on page 713.
During installation, the Certificate Manager creates default CRL extension rules;
these are documented in CMS Plug-ins Guide. Note that the server is configured to
add the CRL Reason extension only; all the other rules are in the disabled state. In
this step, you modify the default CRL extension rules to add the required CRL
extensions.
, or
SHA-1 with RSA
SHA-1 with DSA
Chapter 21
Setting Up a Remote OCSP Responder
. If the Certificate Manager's
.
Setting Up an OCSP Responder
MD2
715

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 4.5 and is the answer not in the manual?

Table of Contents