Setting Up the Issuance of CRLs
Chapter 15
Revocation and CRLs
581
3.
Configure the CRL for this issuing point by specifying the fields in the Revocation List
tab for that issuing point.
You may want to expand the CS console window by dragging at one of the corners,
some fields in this window do not appear large enough to read the content.
In the Update Frequency section, specify the interval for publishing the CRL to the
directory:
Every time a certificate is revoked, or taken off-hold.
Select this option if you want
the Certificate Manager to generate the CRL every time it revokes a certificate. Keep in
mind that the Certificate Manager attempts to publish the CRL to the configured
directory whenever it is generated, in this case, every time a certificate is revoked.
Publishing a CRL can be time consuming if the CRL is large. Configuring the
Certificate Manager to publish CRLs every time a certificate is revoked may engage
the server for a considerable amount of time; during this time, the server will not be
able to update the directory with any changes it receives.
(This setting is not recommended for a standard installation. You can select this option
if you want to see the results of revocation immediately, for example, when testing
whether the server publishes the CRL to a flat file.)
Update at this frequency.
Select this option if you want the Certificate Manager to
generate CRLs at regular intervals. In this case, the server publishes the CRL to the
configured directory at the interval you specify.
In the adjoining text field, type the interval, in minutes, at which the Certificate
Manager should publish CRLs. For example, if you want the server to publish CRLs
every day, you should type 1440 in this field.
with a skew of.
If you configure the Certificate Manager to update the CRL at a
specific frequency, the server by default adds a 5 second skew to the next update time
to allow time to create the CRL and publish it. For example, if you configure the server
to update the CRL every 20 minutes, and if the CRL is updated at 16:00:00, the CRL
will be updated again at 16:19:55. You can change the skew by editing the default
value, which is specified in seconds.
In the CRL Cache section, specify whether to enable CRL caching:
Enable CRL cache.
Select to enable the cache. Note, if the cache is disabled, you
cannot create delta CRLs. For more information about the cache, see “How CRLs
Work,” on page 577.
Cache update interval.
Specifies the period of time when the cache is written to file.
Set to
0
to have the cache written to file every time a certificate is revoked.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...