Configuring a Certificate Manager to Publish Certificates and CRLs
630
Netscape Certificate Management System Installation and Setup Guide • May 2002
2.
In the Update Frequency section, specify the interval for publishing the CRL to
the directory:
Every time a certificate is revoked, or taken off-hold.
Select this option if you
want the Certificate Manager to generate the CRL every time it revokes a
certificate. Keep in mind that the Certificate Manager attempts to publish the
CRL to the configured directory whenever the CRL is generated, in this case,
every time a certificate is revoked. Publishing a CRL can be time consuming if
the CRL is large. Configuring the Certificate Manager to publish CRLs every
time a certificate is revoked may engage the server for a considerable amount
of time; during this time, the server will not be able to service any requests it
receives and will not be able to update the directory with any changes it
receives.
Update at this frequency.
Select this option if you want the Certificate
Manager to generate CRLs at regular intervals. In this case, the server
publishes the CRL to the configured directory at the interval you specify.
In the adjoining text field, type the interval, in minutes, at which the Certificate
Manager should publish CRLs. For example, if you want the server to publish
CRLs every day, you should type 1440 in this field.
with a skew of.
If you configure the server to update the CRL automatically
every time period, the server by default adds a 5 second skew to the next
update time to allow time to create the CRL and publish it. For example, if you
configure the server to update the CRL every 20 minutes, and if the CRL is
updated at 16:00:00, the CRL will be updated again at 16:19:55. You can
configure the skew by changing the default value, which is specified in
seconds.
3.
In the CRL Cache section, specify whether to enable CRL caching:
Enable cache.
Check this box to enable CRL caching. Leave the box unchecked
if you don’t want the server to maintain a cache.
Update interval.
If you enabled caching, type the interval for updating the
cache.
4.
In the CRL Format section, specify the format for publishing the CRL:
Include expired certificates.
Check this box if you want the server to include
revoked certificates that have expired in the CRL.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...