ACL Reference
Chapter 9
Authorization
359
certServer.ocsp.certificate
Allow or deny a validate operation for checking certificate revocation information.
Operations
Default ACIs
allow (validate) group="Online Certificate Status Manager Agents"
Online Certificate Status Manager agents can validate certificate status.
certServer.ocsp.configuration
Allow or deny a read or modify operation to the OCSP configuration.
Operations
Default ACIs
allow (read) group="Administrators" || group=”Certificate Manager
Agents” || group=”Registration Manager Agents” || group=”Data
Recovery Manager Agents” || group=”Online Certificate Status Manager
Agents” || group="Auditors"
allow (modify) group="Administrators"
Administrators, Agents, and auditors are allowed to read OCSP configuration; only
administrators are allowed to modify OCSP configuration.
certServer.ocsp.crl
Allow or deny an add operation for posting CRL to an OCSP.
validate
Checking if the OCSP responder has data indicating that a certificate is
revoked.
read
Viewing OCSP plug-in information, OCSP configuration, OCSP stores
configuration. Listing OCSP stores configuration.
modify
Modifying OCSP configuration, OCSP stores configuration, and default
OCSP store.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...