Chapter 6. Revoking Certificates and Issuing CRLs
182
for generating the key pair and the certificate. If the internal/software token is used, use
Internal Key Storage Token
as the value.
For example, the entries might look like this:
ca.crl_signing.cacertnickname=crlSigningCert cert-pki-ca
ca.crl_signing.defaultSigningAlgorithm=MD5withRSA
ca.crl_signing.tokenname=Internal Key Storage Token
d. Save the changes, and close the file.
9. Restart the Certificate Manager.
service pki-ca restart
Now the Certificate Manager is ready to use the CRL signing certificate to sign the CRLs it
generates.
6.4. Setting Full and Delta CRL Schedules
CRLs are published periodically. Setting that period is touched on in the configuration in
Section 6.3.2,
“Configuring CRLs for Each Issuing Point”
.
First, CRLs are issued according to a time-based schedule. CRLs can be issued every single time a
certificate is revoked, at a specific time of day, or once every so-many minutes.
However, this time-based publishing schedule applies to every CRL that is generated. There are two
kinds of CRLs, however. The full CRL has a record of every single revoked certificate. However, the
Certificate System also publishes a delta CRL, which contains only the certificates that have been
revoked since the last CRL (delta or full) was published.
By default, full and delta CRLs are generated at the same time, and every time. However, it is
possible to space out when full CRLs are published and to publish multiple interim delta CRLs. This is
configured in the
CRL schema
, which sets the scheme for publishing delta and full CRLs.
A full CRL is also called an
extended update
. By default, every CRL publishing period has an
extended update. However, this can be configured so that not every publishing period is an extended
update and to set the interval of when the extended updates are published.
If the interval is set to 3, for example, then the first CRL publishing is both a full and delta CRL, then
the next two publishing updates are only delta CRLs, and then the fourth interval is both a full and
delta CRL again. In other words, every third publishing interval has both a full CRL and a delta CRL.
Interval 1, 2, 3, 4, 5, 6, 7 ...
Full CRL 1 4 7 ...
Delta CRL 1, 2, 3, 4, 5, 6, 7 ...
NOTE
For delta CRLs to be published independent of full CRLs, the CRL cache must be
enabled.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...