Publishing of CRLs
Chapter
19
Setting Up LDAP Publishing
593
Revocation Checking by Netscape Clients
At the time of this writing, Netscape Communicator versions 4.7 and later, when
used in conjunction with the security module called Netscape Personal Security
Manager, enable automatic revocation-status verification of certificates using the
OCSP protocol. Chapter 21, “Setting Up an OCSP Responder” explains how the
revocation status of a certificate is verified in an OCSP-compliant PKI setup.
Earlier versions of Netscape client products do not have the ability to automatically
check to see whether a certificate has been revoked. However, these clients do give
the user the ability to check the revocation status of a certificate if it includes the
NetscapeRevocationURL
extension. For details about this extension, check this
site:
http://home.netscape.com/eng/security/cert-exts.html
In addition, from the Retrieval tab of the CMS end-entity interface, Netscape client
users can manually check the revocation status of a particular certificate and
automatically import the latest version of the CRL into their browsers. If your users
are not using Netscape clients, they can download the latest CRL in binary form to
a local file, and then import this file into their browsers by an appropriate method.
Users can also view the header information of the master or full CRL published by
the Certificate Manager, which contains the date and time of the latest update, and
then compare this information to that in their browser’s CRL to see if they have the
latest version.
Revocation Checking by Netscape Servers
Because Netscape servers currently cannot check the revocation status of a
certificate, you should use other forms of access control. For example, you can
remove individual users from access groups to prevent them from accessing the
server.
Because Certificate Management System can check the revocation status of the
certificates that it issues, you do not need to rely on other forms of access control.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...