Manually Updating The Crl In The Directory - Netscape MANAGEMENT SYSTEM 6.01 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 6.01:
Table of Contents

Advertisement

Manually Updating Certificates and CRLs in a Directory
Note that if the Certificate Manager is installed as a root CA, when using the agent
interface to update the directory with valid certificates, the CA signing certificate
may get published using the publishing rule set up for user certificates and you
may get an object class violation error (or other errors in the mapper). You can
avoid this by selecting the appropriate serial-number range to not include the CA
signing certificate; the CA signing certificate is the first certificate a root CA issues.
If the root CA has issued a subordinate CA certificate, the certificate may also get
published using the publishing rule set up for user certificates, resulting in an
object class violation error. To avoid the problem in publishing the subordinate CA
certificate, you will need to do this:
Modify the default publishing rule for user certificates by changing the value
of the
Use the
with the predicate parameter set to
publishing subordinate CA certificates.

Manually Updating the CRL in the Directory

The Update Certificate Revocation List form in the Certificate Manager Agent
Services interface to enables you to manually update the directory with
CRL-related information.
To manually update the CRL information in the directory:
Go to the Certificate Manager Agent Services page.
1.
You must submit the proper client certificate to get access to this page.
Select Update Revocation List.
2.
The Update Certificate Revocation List page appears.
From the Signature algorithm drop-down list, select the appropriate signature
3.
algorithm.
Click Update.
4.
The Certificate Manager starts updating the directory with the CRL in its
internal database. In some circumstances, for example, if the CRL is large,
updating the directory may take considerable time. During this period, any
changes made to the CRL (for example, any new certificates revoked) may not
be included in the update.
644
Netscape Certificate Management System Installation and Setup Guide • May 2002
parameter to
predicate
LdapCaCertPublisher
HTTP_PARAMS.certType!=ca
publisher plug-in module to add another rule,
HTTP_PARAMS.certType==ca
.
, for

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.01

Table of Contents