157
Chapter 5
OCSP Responder
This chapter provides an overview of an Online Certificate Status Protocol (OCSP) service,
and explains how you can use the OCSP service built into the Certificate Manager for
real-time verification of certificates issued by the Certificate Manager. The chapter also
explains how to install and configure an Online Certificate Status Managers to publish
CRLs.
This chapter contains the following sections:
•
About OCSP Services
•
CS OCSP Services
•
Setting Up a Certificate Manager with OCSP Service
•
Online Certificate Status Manager Deployment Considerations
•
Installing an Online Certificate Status Manager
•
Setting Up the OCSP Responder
•
Configuring the Online Certificate Status Manager
•
Testing Your OCSP Setup
About OCSP Services
CS supports the Online Certificate Status Protocol (OCSP) as defined in the PKIX standard
RFC 2560 (see
http://www.ietf.org/rfc/rfc2560.txt
). The OCSP protocol
enables OCSP-compliant applications to determine the state of a certificate, including the
revocation status, without having to directly check a CRL published by a CA to the
validation authority. The validation authority, which is also called an
OCSP responder
,
does the checking for the application.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...