26.7. Configuring OCSP Responders
Every CA integrated with the IdM server uses an internal online certificate status protocol (OCSP) responder. The IdM service allowing to access the OCSP responders is available at
http://ca-server.example.com/ca/ocsp. Clients can connect to this URL to check the validity of a certificate.
Note
For details on OCSP, see the Red Hat Certificate System documentation. For example, 2.2.4. Revoking Certificates and Checking Status in the Planning, Installation, and Deployment Guide.
26.7.1. Changing the CRL Update Interval Copy linkLink copied to clipboard!
Copy linkLink copied to clipboard!
The CRL file is automatically generated by the IdM CA every four hours by default. To change this interval:
- Stop the CA server.
systemctl stop pki-tomcatd@pki-tomcat.service
# systemctl stop pki-tomcatd@pki-tomcat.serviceCopy to Clipboard Copied! Toggle word wrap Toggle overflow - Open the
/var/lib/pki/pki-tomcat/conf/ca/CS.cfgfile, and change theca.crl.MasterCRL.autoUpdateIntervalvalue to the new interval setting. For example, to generate the CRL every 60 minutes:ca.crl.MasterCRL.autoUpdateInterval=60
ca.crl.MasterCRL.autoUpdateInterval=60Copy to Clipboard Copied! Toggle word wrap Toggle overflow NoteIf you update theca.crl.MasterCRL.autoUpdateIntervalparameter, the change will become effective after the next already scheduled CRL update. - Start the CA server.
systemctl start pki-tomcatd@pki-tomcat.service
# systemctl start pki-tomcatd@pki-tomcat.serviceCopy to Clipboard Copied! Toggle word wrap Toggle overflow