Setting Up a Remote OCSP Responder
Chapter
21
Setting Up an OCSP Responder
687
3.
Select the certificate you revoked and click View.
In the View Security Certificate dialog box that appears, look for a message
that says that the certificate could not be verified.
Step J. Check the Certificate Manager’s OCSP Service Status Again
Check the Certificate Manager’s OCSP-service status again to verify that these
things happened:
•
The browser sent an OCSP query to the Certificate Manager (this response was
initiated when you clicked the View button).
•
The Certificate Manager sent an OCSP response to the browser.
•
The browser used that response to validate the certificate and informed you of
its status (that the certificate could not be verified).
To check the Certificate Manager’s OCSP-service status for verification:
1.
Go to the Certificate Manager’s status page.
2.
Reload the page (hold down the Shift key and click on the browser’s Reload
icon.)
3.
Compare the information to the one you noted in Step G above.
The updated statistics should indicate that Personal Security Manager queried
the Certificate Manager about the status of the certificate and in response, the
Certificate Manager informed Personal Security Manager that the certificate is
revoked.
Setting Up a Remote OCSP Responder
You can configure a Certificate Manager to publish CRLs to an online certificate
validation authority, such as the one included with Certificate Management
System, and then issue end-entity certificates with Authority Information Access
extension pointing to the location at which the OCSP responder waits for queries
about revocation status of certificates.
This section explains how to set up a Certificate Manager functioning as a root CA
to publish CRLs to a remote Online Certificate Status Manager and configure
OCSP-compliant clients to query the Online Certificate Status Manager for
revocation status of certificates being validated.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...