Configuring Issuing Points
175
•
ARL
is an Authority Revocation List containing only revoked CA certificates.
•
CRL with expired certificates
includes revoked certificates that have expired in the CRL.
•
CRL from certificate profiles
determines the revoked certificates to include based on the profiles
used to create the certificates originally.
3. Configure the CRLs for each issuing point. See
Section 6.3.2, “Configuring CRLs for Each Issuing
Point”
for details.
4. Set up the CRL extensions which are configured for the issuing point. See
Section 6.3.3, “Setting
CRL Extensions”
for details.
5. Set up the delta CRL for an issuing point by enabling extensions for that issuing point,
DeltaCRLIndicator
or
CRLNumber
.
6. Set up the
CRLDistributionPoint
extension to include information about the issuing point.
7. Set up publishing CRLs to files, an LDAP directory, or an OCSP responder. See
Chapter 8,
Publishing Certificates and CRLs
for details about setting up publishing.
6.3.1. Configuring Issuing Points
Issuing points define which certificates are included in a new CRL. A master CRL issuing point is
created by default for a master CRL containing a list of all revoked certificates for the Certificate
Manager.
To create a new issuing point, do the following:
1. Open the Certificate System Console.
pkiconsole https://server.example.com:9445/ca
2. In the
Configuration
tab, select
Certificate Manager
from the left navigation menu. Then select
CRL Issuing Points
.
3. To edit an issuing point, select the issuing point, and click
Edit
. The only parameters which can be
edited are the name of the issuing point and whether the issuing point is enabled or disabled.
To add an issuing point, click
Add
. The CRL Issuing Point Editor window opens.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...