openLDAP with CRL

2010-04-10 Thread shake kvc
Hi, I want to be able to store CRLs in the openldap repository so that I can retrieve them using a LDAP client. Basically, the client would be given a LDAP URL as follows: ldap://xxx.yyy.com/CN=Challenger(1),CN=xxx,CN=C

Re: openLDAP with CRL

2010-04-10 Thread Michael Ströder
shake kvc wrote: I want to be able to store CRLs in the openldap repository so that I can retrieve them using a LDAP client. Basically, the client would be given a LDAP URL as follows: ldap://xxx.yyy.com/CN=Challenger(1),CN=xxx,CN=C

Re: openLDAP with CRL

2010-04-10 Thread Patrick Patterson
Hi there: One other thing to keep in mind is that the DN for the CRLDP *SHOULD* be the same as that for the CA that signs the CRL. I believe this is a Best Practice, and not completely normative, but it is well enough enshrined (USFBCA CP and all cross-certified CA's, Canadian Govn't, etc.), that