Admin Guide
vi
6.4.1. Configuring Extended Updated Intervals for CRLs in the Console .............. 183
6.4.2. Configuring Extended Updated Intervals for CRLs in CS.cfg ...................... 183
6.5. Enabling Automatic Revocation Checking for Agent Certificates ........................... 184
7. Using the Online Certificate Status Protocol Responder 187
7.1. Setting up the OCSP Responder ....................................................................... 187
7.2. Identifying the CA to the OCSP Responder ........................................................ 188
7.2.1. Verify Certificate Manager and Online Certificate Status Manager
Connection ...................................................................................................... 189
7.2.2. Configure the Revocation Info Stores ...................................................... 189
7.2.3. Testing the OCSP Service Setup ............................................................ 190
7.3. Enabling the Certificate Manager's Internal OCSP Service ................................... 191
7.4. Enabling Revocation Checking for the TPS and RA ............................................ 192
7.5. Enabling Certificate Revocation Checking for DRM and TKS Users ...................... 194
7.6. Submitting OCSP Requests Using the GET Method ............................................ 196
7.7. Setting up a Redirect for Certificates Issued in Certificate System 7.1 and Earlier
... 197
II. Additional Configuration to Manage CA Services 201
8. Publishing Certificates and CRLs 203
8.1. About Publishing .............................................................................................. 203
8.1.1. Publishers ............................................................................................. 204
8.1.2. Mappers ................................................................................................ 205
8.1.3. Rules .................................................................................................... 205
8.1.4. Publishing to Files ................................................................................. 205
8.1.5. OCSP Publishing ................................................................................... 205
8.1.6. LDAP Publishing .................................................................................... 206
8.2. Setting up Publishing ........................................................................................ 206
8.2.1. Configuring Publishing to a File .............................................................. 207
8.2.2. Configuring Publishing to an OCSP ......................................................... 210
8.2.3. Configuring Publishing to an LDAP Directory ........................................... 211
8.2.4. Creating Rules ....................................................................................... 217
8.2.5. Enabling Publishing ................................................................................ 221
8.3. Publishing CRLs over HTTP ............................................................................. 222
8.3.1. Configuring CRL Publishing to Resume after Interrupted Downloads .......... 223
8.3.2. Retrieving CRLs Using wget ................................................................... 228
8.3.3. Retrieving Partial CRLs .......................................................................... 228
8.4. Publishing Cross-Pair Certificates ...................................................................... 229
8.5. Testing Publishing to Files ................................................................................. 230
8.6. Viewing Certificates and CRLs Published to File ................................................. 231
8.7. Updating Certificates and CRLs in a Directory .................................................... 231
8.7.1. Manually Updating Certificates in the Directory ........................................ 232
8.7.2. Manually Updating the CRL in the Directory ............................................ 233
8.8. Registering and Deleting Mapper and Publisher Plug-in Modules ......................... 233
9. Authentication for Enrolling Certificates 235
9.1. Configuring Agent-Approved Enrollment ............................................................. 235
9.2. Automated Enrollment ....................................................................................... 236
9.2.1. Setting up Directory-Based Authentication ............................................... 236
9.2.2. Setting up PIN-Based Enrollment ............................................................ 238
9.2.3. Using Certificate-Based Authentication .................................................... 241
9.2.4. Configuring Flat File Authentication ......................................................... 241
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...