Using Certificates with HP-UX IPSec

Retrieving the Certificate Revocation List (CRL)

[min] [hr] [mon_day] [month] [wkday] /var/adm/ipsec_gui/cron/baltimoreCRL.cron

The fields in brackets are placeholders. Replace them with appropriate values when you enter the lines into the crontab file.

For example, to retrieve the CRL every hour on the hour, add the following two lines to the crontab file:

#Retrieve the CRL from the Certificate Authority (for HP-UX IPSec)

0 * * * * /var/adm/ipsec_gui/cron/baltimoreCRL.cron

Execute the crontab command to submit the root crontab file:

crontab /var/spool/cron/crontabs/root

For more information regarding cron jobs and the crontab file format, refer to the cron (1M) and crontab (1) manpages.

Manually Retrieving a CRL for VeriSign or Baltimore

Use the following procedure to manually retrieve a CRL:

1.Click Get CRL on the Certificates tab of ipsec_mgr.

2.A screen appears that tells you to wait for the system to retrieve the CRL.

Chapter 4

143