Renewal; Revocation - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

How a Registration Manager Works
The certificate that was issued is stored in the internal database of the
Certificate Manager.
You can set up publishing in the Certificate Manager, in which case the
certificate will be published according to the rules set up in the Certificate
Manager.
If the OCSP service of the Certificate Manager is enabled, requests for the
status of this certificate can be made to the Certificate Manager through this
service.

Renewal

The Registration Manager allows for the renewal of certificates. Certificates can be
renewed if the policies associated with renewal are enabled and if the request
meets the criteria of those policies, and if the policies associated with renewal are
enabled in the Certificate Manager and if the request meets the criteria of those
policies that are set up in the Certificate Manager. The Registration Manager is set
up for a single method of renewal. All requests are made to the renewal page of the
end-entity interface. The end entity presents their old certificate, and if they meet
the policies for renewal, a new certificate is issued with the validity period set up in
the renewal policies.
The Registration Manager does not send automated renewal notifications, the
Certificate Manager that issues the certificate must have this feature set up for
renewal messages to be sent to end entities.

Revocation

An end entity can request that their own certificate is revoked.
When an end entity makes the request, they are asked to present the certificate. If
they have the certificate and the key materials, the request is processed and sent to
the Certificate Manager and the certificate is revoked. Once approved, the signed
request is sent to the Certificate Manager and the certificate is revoked. The
Certificate Manager marks the certificate as revoked in its database, and adds it to
any CRLs that are applicable. If the Certificate Manager has the Certificate Revoked
notification set up, it sends an email message to the end entity when the certificate
is revoked.
164
Netscape Certificate Management System Administrator's Guide • February 2003

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents