Configure The Revocation Info Stores - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Configure the Revocation Info Stores

The Online Certificate Status Manager stores each Certificate Manager's CRL in its
internal database and uses it as the default CRL store for verifying the revocation
status of certificates. You can also configure the Online Certificate Status Manager
to use the CRL published to an LDAP directory, instead of the CRL in its internal
database. For example, if you've configured Certificate Managers to publish CRLs
to LDAP directories (see Chapter 15, "Publishing"), you can configure the Online
Certificate Status Manager to use the CRLs published to these directories.
To configure the Online Certificate Status Manager to use the CRLs in its internal
database or an LDAP directory for verifying revocation status of certificate:
Log in to the CMS window for the Online Certificate Status Manager (see
1.
"Logging Into the CMS Console" on page 247).
Select the Configuration tab.
2.
In the navigation tree, select Online Certificate Status Manager, and then select
3.
Revocation Info Stores.
The right pane shows the two repositories the Online Certificate Status
Manager can use; by default, it uses the CRL in its internal database.
Select the appropriate option:
4.
If you want to configure the Online Certificate Status Manager to use the
CRLs in its internal database, select
If you want to configure the Online Certificate Status Manager to use the
CRLs in one or more directories, first click Set Default to enable the
option, select
ldapStore
Default toggles the selection between the two repositories.)
The Revocation Info Store Editor for the selected store appears.
Fill in the appropriate values.
5.
If you selected
notFoundAsGood. A certificate's status can typically be indicated by three
possible OCSP responses, namely GOOD, REVOKED, and UNKNOWN.
Select this option if you want the Online Certificate Status Manager to
return an OCSP response of GOOD if the certificate in question cannot be
found in any of the CRLs. If you deselect the option, the response will be
UNKNOWN, which when encountered by an OCSP-compliant client
results in an error message.
ldapStore
, fill in values as below:
defStore
Configuring the Online Certificate Status Manager
and click Edit/View.
defStore
, and click Edit/View. (Clicking Set
Chapter 5
OCSP Responder
195

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents