Manually Updating Certificates and CRLs in a Directory
644
Netscape Certificate Management System Installation and Setup Guide • May 2002
Note that if the Certificate Manager is installed as a root CA, when using the agent
interface to update the directory with valid certificates, the CA signing certificate
may get published using the publishing rule set up for user certificates and you
may get an object class violation error (or other errors in the mapper). You can
avoid this by selecting the appropriate serial-number range to not include the CA
signing certificate; the CA signing certificate is the first certificate a root CA issues.
If the root CA has issued a subordinate CA certificate, the certificate may also get
published using the publishing rule set up for user certificates, resulting in an
object class violation error. To avoid the problem in publishing the subordinate CA
certificate, you will need to do this:
•
Modify the default publishing rule for user certificates by changing the value
of the
predicate
parameter to
HTTP_PARAMS.certType!=ca
.
•
Use the
LdapCaCertPublisher
publisher plug-in module to add another rule,
with the predicate parameter set to
HTTP_PARAMS.certType==ca
, for
publishing subordinate CA certificates.
Manually Updating the CRL in the Directory
The Update Certificate Revocation List form in the Certificate Manager Agent
Services interface to enables you to manually update the directory with
CRL-related information.
To manually update the CRL information in the directory:
1.
Go to the Certificate Manager Agent Services page.
You must submit the proper client certificate to get access to this page.
2.
Select Update Revocation List.
The Update Certificate Revocation List page appears.
3.
From the Signature algorithm drop-down list, select the appropriate signature
algorithm.
4.
Click Update.
The Certificate Manager starts updating the directory with the CRL in its
internal database. In some circumstances, for example, if the CRL is large,
updating the directory may take considerable time. During this period, any
changes made to the CRL (for example, any new certificates revoked) may not
be included in the update.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...