Setting Up a Certificate Manager with OCSP Service
Chapter
21
Setting Up an OCSP Responder
679
a.
Select the Advanced tab.
b.
On the left side, select Options, and then click the OCSP Settings button.
c.
In the OCSP Settings window, select the “Use OCSP to verify only
certificates that specify an OCSP service URL.” option and click OK.
Step 3. Enable Certificate Manager’s HTTP Port
The Certificate Manager services OCSP requests via its nonSSL (HTTP) end-entity
port; see “End-Entity Ports” on page 361. If you’ve disabled the port, you must
enable it so that OCSP-compliant clients can successfully query the Certificate
Manager for the revocation status of a certificate.
To enable the end-entity port used by the Certificate Manager for non-SSL
communications, see “Configuring Port Numbers” on page 362.
Step 4. Configure Certificate Manager for
Extensions
In order for OCSP-compliant clients to query the Certificate Manager about the
revocation status of a certificate, the certificate being validated must contain the
Authority Information Access extension pointing to the location at which the
Certificate Manager listens for OCSP service requests. For details about the
Authority Information Access extension, see section “AuthInfoAccessExt Plug-in
Module” of CMS Plug-Ins Guide.
The Certificate Manager can add an extension to a certificate it issues only if the
corresponding policy is enabled and configured properly. Hence, before issuing
the OCSP-compliant client certificate, you must verify that the Certificate Manager
is configured with the appropriate policy rules to add the required extensions to
these certificates.
•
During the installation of a Certificate Manager, if you chose to enable its
OCSP service, a default policy rule (named
AuthInfoAccessExt
) is created
with correct attributes for adding the Authority Information Access extension
to certificates the Certificate Manager will issue following installation. If you
didn’t make any changes to the policy configuration of the Certificate
Manager, you probably don’t need to do anything.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...