Chapter 6. Revoking Certificates and Issuing CRLs
174
revoker -d "/var/lib/pki-ca/alias" -n "ManagerAgentCert" -i "cn=agentAuthMgr" -s 22 -m 0 -
c "test comment"
2. Open the end-entities page.
http
s
://server.example.com:
9444/ca/ee/ca
3. Select the
Revocation
tab.
4. Select the
CMC Revoke
link on the menu.
5. Paste the output from the
revoker
into the text area.
6. Remove
-----BEGIN NEW CERTIFICATE REQUEST-----
and
----END NEW CERTIFICATE
REQUEST-----
from the pasted content.
7. Click
Submit
.
8. The returned page should confirm that correct certificate was been revoked.
6.3. Issuing CRLs
1. The Certificate Manager uses its CA signing key to sign CRLs. To use a separate signing key pair
for CRLs, set up a CRL signing key and change the Certificate Manager configuration to use this
key to sign CRLs. See
Section 6.3.4, “Setting a CA to Use a Different Certificate to Sign CRLs”
for
more information.
2. Set up CRL issuing points. An issuing point is already set up and enabled for a master CRL.
Figure 6.1. Default CRL Issuing Point
Additional issuing points for the CRLs can be created. See
Section 6.3.1, “Configuring Issuing
Points”
for details.
There are four types of CRLs the issuing points can create, depending on the options set when
configuring the issuing point to define what the CRL will list:
•
Master CRL
contains the list of revoked certificates from the entire CA.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...