Hp Secure Key Manager Manuale Utente Pagina 153

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
Vedere la pagina 152
Figure 92 Viewing the Install CA Certicate section
The following table describes the components of the Install CA Certicate section.
Table 71 Install CA Certicate section components
Component Description
Certicate Name Enter the certicate name.
Certicate Paste the contents of the certicate.
Install Click Install to install the CA.
Support for Certicate Revocation Lists
Certicate Authorities regularly publish a list of certicates that have been revoked by that CA. Such a list
is called a certicate revocation list (CRL). The list of revoked certicates is distributed in X.509 CRL v2
format. Support for CRLs on the SKM allows you to obtain, query, and maintain CRLs published by CAs
supported on the SKM. The SKM uses CRLs to verify certicates in two ways.
Require Client Authentication – when enabled, the SKM only accepts connections from clients
that present a valid client certicate. As certicates are presented to the SKM, they are checked
against the CRL published by the CA who issued the certicate.
Web Administration User Authentication – when enabled, this option species that you cannot
log in to the Management Console without presenting a valid client certicate. As certicates
are presented to the SKM, they are checked against the CRL published by the CA who issued
the certicate.
You can congure the SKM to fetch the CRL at a regular interval. The CRL is transported to the SKM via
FTP, SCP or HTTP. The SKM ca n only be congured to retrieve complete CRLs, as opposed to partial,
delta, or indirect CRLs. You can also manually download updated CRLs to the SKM.
The SKM validates all CRLs that it downloads. For the SKM to validate a CRL, the CA that signed the
CRL must be in the list of Trusted CAs on the SKM. CRLs published by untrusted CAs are rejected by the
SKM. Once a CRL is installed on the SKM, it remains in effect on the device until the CRL is successfully
updated by a CRL from the same issuing CA. If a CRL has been signed with a key that does not match the
key in the CA certicate on the SKM, the validation of the CRL fails.
When a certicate on the SKM appears on a CRL, the event is logged in System Log. Traps for revoked
certicates are sent daily around 5:10 AM local time.
Local CAs
The CRL functionality allows you to revoke and renew certicates that are signed with local CAs.
Additionally, you can export a CRL issued by local CAs. CRLs exported from the SKM contain a list of
Secure Key Manager
153
Vedere la pagina 152
1 2 ... 148 149 150 151 152 153 154 155 156 157 158 ... 326 327

Commenti su questo manuale

Nessun commento