Crl Issuing Points; Delta Crls; How Crls Work - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

About CRLs
For information on setting up an OCSP responder, see Chapter 5, "OCSP
Responder."

CRL Issuing Points

Because CRLs can grow very large, several methods have been developed to
minimize the overhead of retrieving and delivering large CRLs. One of these
methods is based on partitioning the entire certificate space and associating a
separate CRL with every partition. This partition is called a CRL issuing point—it is
the location where a subset of all the revoked certificates are maintained.
Partitioning can be based on whether the revoked certificate is a CA certificate or
end-entity certificate. Each issuing point is identified by its name.
Once the issuing points have been defined, they can be included in certificates so
that an application that needs to check the revocation status of a certificate can
access the CRL issuing points specified in the certificate instead of the master or
main CRL—the application would check the CRL maintained at the issuing point,
which would be smaller in size compared to the master CRL, and thus speed up
the revocation-status-checking process.
CRL distribution points can be associated with certificates by setting the
extension in them.
CRLDistributionPoint
By default, the Certificate Manager only generates and publishes a single CRL,
identified as the master CRL. You can also define an issuing point for CA signing
certificates, and an issuing point that includes all revoked certificate information
including expired certificates.

Delta CRLs

You can issue Delta CRLs for any issuing point defined. A delta CRL will contain
information about any certificates revoked since the last update to the full CRL.
You set up Delta CRLs for an issuing point by enabling the
DeltaCRLIndicator
extension.

How CRLs Work

You set up the generation of CRLs by specifying issuing points, configuring those
issuing points, and setting up CRL extensions, if desired.
Chapter 14
Revocation and CRLs
601

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR and is the answer not in the manual?

Subscribe to Our Youtube Channel

This manual is also suitable for:

Certificate management system 6.1

Table of Contents