Verify Certificate Manager and Online Certificate Status Manager Connection
189
7.2.1. Verify Certificate Manager and Online Certificate Status
Manager Connection
When the Certificate Manager is restarted, it tries to connect to the Online Certificate Status Manager's
SSL port. To verify that the Certificate Manager did indeed communicate with the Online Certificate
Status Manager, check the
This Update
and
Next Update
fields, which should be updated with the
appropriate timestamps of the CA's last communication with the Online Certificate Status Manager.
The
Requests Served Since Startup
field should still show a value of zero (0) since no client has
tried to query the OCSP service for certificate revocation status.
7.2.2. Configure the Revocation Info Stores
The Online Certificate Status Manager stores each Certificate Manager's CRL in its internal database
and uses it as the CRL store for verifying the revocation status of certificates. The Online Certificate
Status Manager can be configured to use the CRL published to an LDAP directory, instead of the CRL
in its internal database.
To configure the Online Certificate Status Manager to use the CRLs in its internal database or an
LDAP directory for verifying revocation status of certificate, do the following:
1. Open the Online Certificate Status Manager Console.
pkiconsole https://server.example.com:11445/ocsp
2. In the
Configuration
tab, select
Online Certificate Status Manager
, and then select
Revocation
Info Stores
.
The right pane shows the two repositories the Online Certificate Status Manager can use; by
default, it uses the CRL in its internal database.
3. Select the appropriate option:
• To use the CRLs in its internal database, select
defStore
, and click
Edit/View
.
• To use the CRLs in LDAP directories, click
Set Default
to enable the
ldapStore
option, select
ldapStore
, and click
Edit/View
.
4. For
defStore
, fill in the following values:
•
notFoundAsGood.
Sets the OCSP service to return an OCSP response of GOOD if the
certificate in question cannot be found in any of the CRLs. If this is not selected, the response is
UNKNOWN, which, when encountered by a client, results in an error message.
•
includeNextUpdate.
The Online Certificate Status Manager can include the timestamp of the
next CRL update time.
For
ldapStore
, fill in the following values:
•
numConns.
The total number of LDAP directories the OCSP service should check. By default,
this is set to 0. Setting this value shows the corresponding number of
host
,
port
,
baseDN
, and
refreshInSec
fields.
•
host.
The fully-qualified DNS hostname of the LDAP directory.
•
port.
The non-SSL port of the LDAP directory.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...