Privileged-User Types and Responsibilities
380
Netscape Certificate Management System Installation and Setup Guide • May 2002
To configure a Certificate Manager or Registration Manager to verify the
revocation status of its agents’ certificates:
1.
Stop the CMS instance; see “Stopping Certificate Management System” on
page 310.
2.
Go to this directory:
<server_root>/cert-<instance_id>/config
3.
Open the configuration file (
CMS.cfg
) in a text editor.
4.
Locate the parameters mentioned above and edit their values as appropriate.
5.
Save your changes, and close the configuration file.
6.
Start the CMS instance; see “Starting Certificate Management System” on
page 306.
Trusted Managers
Trusted managers are those CMS subsystems or managers that are connected to
other CMS subsystems and that are trusted to perform specific functions for them.
In other words, a trusted manager acts as a front end to the subsystem that trusts it,
performing specific functions, depending on the subsystem to which it is
connected. You establish this trust between the two subsystems by configuring
them to function in certain way.
revocationChecking.
unknownStateInterval
The default interval is o seconds.
revocationChecking.
validityInterval
Specifies how long, in seconds, the cached certificates are
considered valid. Be judicious when choosing the interval,
especially when configuring a Registration Manager. For
example, if you configure the validity period to be 60 seconds,
the server discards the certificates in its cache every minute
and attempts to retrieve them from their source—the
Certificate Manager uses its internal database to retrieve and
verify the revocation status of the certificates, whereas the
Registration Manager retrieves certificates from its own
internal database and then requests the Certificate Manager
for the revocation status of these certificates.
The default validity period is 120 seconds (2 minutes).
Table 13-1
Configuration parameters for checking the revocation status of agents’ certificates (Continued)
Parameter name
Description
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...