Setting Up The Issuance Of Crls - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Setting Up the Issuance of CRLs

The process of setting up the CRL feature includes the following tasks:
The Certificate Manager will use its CA signing key to sign CRLs. If you want
1.
to use a separate signing key pair for CRLs, you need to set up a CRL singing
key and change the Certificate Manager configuration to allow it to use this key
to sign CRLs. See "Getting a CRL Signing Key Pair and Certificate," on page
112 for details on setting this up.
Setting up CRL Issuing Points by enabling those you want to actually issue
2.
CRLs. An issuing point is already set up and enabled for a Master CRL. You
can create any additional Issuing Points you want for the CRLs you want to
generate from those issuing points. See "Configuring Issuing Points," on page
604 for complete details.
There are three possible issuing points you can create, select the correct options
when configuring the issuing point to define what the CRL will list:
Master CRL. Containing the list of revoked certificates from the entire CA.
ARL. Authority Revocation List containing only revoked CA certificates.
Master CRL and Expired Certificates. Containing the list of revoked
certificates from the entire CA that also includes revoked certificates that have
expired.
Configuring the CRLs for each issuing point by setting the parameters in the
3.
Revocation List tab for that issuing point. See "Configuring CRLs for Each
Issuing Point," on page 605 for complete details.
Setting up the CRL extensions if you turned on extensions when you
4.
configured the issuing point. See "Setting CRL Extensions," on page 607 for
complete details.
If you want to set up Delta CRLs for a particular issuing point, you need to
5.
enable extensions for that issuing point, and enable and configure the
DeltaCRLIndicator
Setting up the
6.
want to include information about the issuing point where CRLs can be found
for that certificate. See Chapter 11, "Policies" for information about setting up
policies for constraints and certificate extensions; see
"CRLDistributionPointsExt," on page 522 for specifics on setting up the
CRLDistributionPoint
or
.
CRLNumber
CRLDistributionPoint
extension in certificates you issue.
Setting Up the Issuance of CRLs
extension in certificates you issue if you
Chapter 14
Revocation and CRLs
603

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents