Publishing of Certificates to a Directory
588
Netscape Certificate Management System Installation and Setup Guide • March 2002
The publishing directory is updated at these times:
•
When the Certificate Manager starts up, it publishes its CA signing certificate to
the directory.
•
When the Certificate Manager issues a new certificate (the request may
originate from Registration Managers that’re connected to the Certificate
Manager), it stores a copy of the certificate in its internal database and then
publishes the certificate to the configured directory.
•
When the Certificate Manager revokes a certificate (the request may originate
from Registration Managers that’re connected to the Certificate Manager), it
marks the copy of the certificate in its internal database as revoked and then
unpublishes or removes the revoked certificate from the configured directory.
•
When a certificate expires, the Certificate Manager can remove that certificate
from the configured directory. Note that the server doesn’t do this
automatically. You need to configure the server to run the appropriate job. For
details, see “Configuring a Subsystem to Run Automated Jobs” on page 545.
•
When the certificate revocation list is created or updated (either through the
CMS window or through the certificate-revocation feature provided in the
agent or end-entity interface), the Certificate Manager publishes that list to the
configured directory.
Table 19-1 summarizes the above-listed actions of the Certificate Manager. The
table also indicates how the Certificate Manager populates an LDAP directory, if
configured for publishing. Note that certificates (and CRLs) are published as
DER-encoded binary blobs.
Table 19-1
Details of objects published by the Certificate Manager
Object
Action and Timing
LDAP entry
LDAP attribute
End-entity
certificate
Publishing occurs when a certificate
is issued or renewed
End-entity’s
entry
userCertificate;binary
Unpublishing (removal) occurs
when a certificate is revoked or
expired
End-entity’s
entry
userCertificate;binary
CA certificate
Publishing occurs when the
Certificate Manager is started
CA’s entry
caCertificate;binary
CRL (full)
Publishing (replacement) occurs
when a new CRL is generated
CA’s entry
certificateRevocation
List;binary
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...