certServer.ocsp.cas
517
D.5.5. certServer.ocsp.cas
Controls who can list, in the agent services interface, all of the Certificate Managers which publish
CRLs to the Online Certificate Status Manager. The default setting is:
allow (list) group="Online Certificate Status Manager Agents"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
list
Lists all of the Certificate Managers which publish CRLs to the OCSP responder.
Allow
Agents
Table D.70. certServer.ocsp.cas ACL Summary
D.5.6. certServer.ocsp.certificate
Controls who can validate the status of a certificate. The default setting is:
allow (validate) group="Online Certificate Status Manager Agents"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
validate
Verifies the status of a specified certificate.
Allow
Agents
Table D.71. certServer.ocsp.certificate ACL Summary
D.5.7. certServer.ocsp.configuration
Controls who can access, view, or modify the configuration for the Certificate Manager's OCSP
services. The default configuration is:
allow (read) group="Administrators" || group="Certificate Manager Agents" ||
group="Registration Manager Agents" || group="Data Recovery Manager Agents" || group="Online
Certificate Status Manager Agents" || group="Auditors";allow (modify) group="Administrators"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View CRL plug-in information, general CA configuration, CA connector configuration, CRL issuing points configuration, CRL configuration, request
notification configuration, revocation notification configuration, request in queue notification configuration, and CRL extensions configuration. List CRL
extensions configuration and CRL issuing points configuration.
Allow
Administrators
Agents
Auditors
modify
Add and delete CRL issuing points. Modify general CA settings, CA connector configuration, CRL issuing points configuration, CRL configuration,
request notification configuration, revocation notification configuration, request in queue notification configuration, and CRL extensions configuration.
Allow
Administrators
Table D.72. certServer.ocsp.configuration ACL Summary
D.5.8. certServer.ocsp.crl
Controls access to read or update CRLs through the agent services interface. The default setting is:
allow (add) group="Online Certificate Status Manager Agents"
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...