Skip to content

Installing OCSP with Existing DS Backend

Endi S. Dewata edited this page Sep 14, 2023 · 1 revision

Table of Contents

Overview

This page describes the process to install OCSP with an existing DS backend (e.g. userRoot).

Preparing DS Instance

Add a PKI top-level entry in the default DS backend with the following command:

$ ldapadd -x -D "cn=Directory Manager" -w Secret.123 << EOF
dn: dc=pki,dc=example,dc=com
objectClass: domain
dc: pki
EOF

Installing OCSP

Prepare a deployment configuration file (e.g. ocsp.cfg):

[DEFAULT]
pki_server_database_password=Secret.123

[OCSP]
pki_admin_cert_file=/root/.dogtag/pki-tomcat/ca_admin.cert
pki_admin_email=ocspadmin@example.com
pki_admin_name=ocspadmin
pki_admin_nickname=ocspadmin
pki_admin_password=Secret.123
pki_admin_uid=ocspadmin

pki_client_database_password=Secret.123
pki_client_database_purge=False
pki_client_pkcs12_password=Secret.123

pki_ds_base_dn=dc=ocsp,dc=pki,dc=example,dc=com
pki_ds_database=userRoot
pki_ds_create_new_db=False
pki_ds_password=Secret.123

pki_security_domain_name=EXAMPLE
pki_security_domain_user=caadmin
pki_security_domain_password=Secret.123

pki_ocsp_signing_nickname=ocsp_signing
pki_audit_signing_nickname=ocsp_audit_signing
pki_sslserver_nickname=sslserver
pki_subsystem_nickname=subsystem

To begin the installation, execute the following command:

$ pkispawn -f ocsp.cfg -s OCSP

Verification

Verify that OCSP is running with the following command:

$ pki -d ~/.dogtag/pki-tomcat/ca/alias -c Secret.123 -n caadmin ocsp-user-show ocspadmin
----------------
User "ocspadmin"
----------------
  User ID: ocspadmin
  Full name: ocspadmin
  Email: ocspadmin@example.com
  Type: adminType
  State: 1

See Also

Clone this wiki locally