Online Certificate Status Manager Deployment Considerations; Online Certificate Status Manager Certificates - Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Online Certificate Status Manager Deployment Considerations

Set up CRLs. You need to configure the Certificate Manager to issue CRLs. See
2.
Chapter 14, "Revocation and CRLs" for details on configuring CRLs.
You must configure your policies or certificate profiles to include the Authority
3.
Information Access extension pointing to the location at which the Certificate
Manager listens for OCSP service requests (identified as the
AuthInfoAccessExt
issued. This extension is necessary to identify the OSCP service. If you installed
the Certificate Manager with the OSCP service on, this extension is created
with the correct information for the OSCP service in the policy framework, and
is not enabled by default. If you chose not to configure the OSCP service, you
will have to create this policy and configure it for this service.
If you installed the Certificate Manager's with its OCSP service feature
disabled, a default policy rule (named
may not have the correct attributes for adding the Authority Information
Access extension to certificates.
See Chapter 11, "Policies" for details on configuring policies, see
"AuthInfoAccessExt," on page 508 for specific information on this policy
module.
Make sure the OCSP SSL signing certificate is from a CA that is trusted by the
4.
Certificate Manager. See "OCSP Certificates," on page 189 for more
information.
Online Certificate Status Manager Deployment
Considerations
This section describes the decisions you make during installation that will apply to
your initial configuration of the subsystem.

Online Certificate Status Manager Certificates

When you install the Online Certificate Status Manager, the keys for the OCSP
signing certificate and SSL server certificate are created and a certificate request is
made for the signing certificate and the SSL server certificate.
170
Netscape Certificate Management System Administrator's Guide • June 2003
instance in the policy framework.) in certificates that are
AuthInfoAccessExt
) is created, but it

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents