Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 342

Table of Contents

Advertisement

Agent Certificates
NOTE
The configuration files of both Certificate Manager and Registration Manager
include parameters that enable you to specify whether the server should do the
revocation checking and if it should, at what interval. Note that the
revocation-status verification works for only those agent certificates that have been
issued by the Certificate Manager (and not by any third-party CAs).
To configure a Certificate Manager or Registration Manager to verify the
revocation status of its agents' certificates:
Stop the CMS instance; see "Starting, Stopping, and Restarting CMS Instances"
1.
on page 254.
Go to the following directory:
2.
<server_root>/cert-<instance_id>/config
Open the
3.
Edit the following parameters as appropriate.
4.
revocationChecking.bufferSize
revocationChecking.<subsystem>
342
Netscape Certificate Management System Administrator's Guide • February 2003
The CMS configuration file (
jss.ocspcheck.enable
CMS manager should use Online Certificate Status Protocol (OCSP)
to verify the revocation status of the certificate it receives as a part
of SSL client or server authentication (from clients or servers it
makes connections with). If you change the value of this parameter
to
, the CMS manager reads the Authority Information Access
true
extension in the certificate and verifies the revocation status of the
certificate from the OCSP responder specified in the extension.
file in a text editor.
CMS.cfg
) includes a parameter named
CMS.cfg
, which enables you to specify whether a
Specifies the total number of last-checked
certificates the server should maintain in its
cache. For example, if you configure the
buffer size to be 2, the server retains the last
two certificates it checked in its cache. By
default, the server caches the last 50
certificates.
Specifies the name of the CMS instance.
<subsystem> indicates whether the
subsystem is a Certificate Manager (ca) or
Registration Manager (ra). You must not
change the default values.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents