Administration

Table Of Contents
Smart Card Certificate Revocation Checking Properties
You set values in the locked.properties le to enable and congure smart card certicate revocation
checking.
Table 3-1 lists the locked.properties le properties for certicate revocation checking.
Table 31. Properties for Smart Card Certificate Revocation Checking
Property Description
enableRevocationChecking Set this property to true to enable certicate revocation
checking.
When this property is set to false, certicate revocation
checking is disabled and all other certicate revocation
checking properties are ignored.
The default value is false.
crlLocation
Species the location of the CRL, which can be either a
URL or a le path.
If you do not specify a URL, or if the specied URL is
invalid, View uses the list of CRLs on the user certicate if
allowCertCRLs is set to true or is not specied.
If View cannot access a CRL, CRL checking fails.
allowCertCRLs When this property is set to true, View extracts a list of
CRLs from the user certicate.
The default value is true.
enableOCSP Set this property to true to enable OCSP certicate
revocation checking.
The default value is false.
ocspURL
Species the URL of an OCSP Responder.
ocspResponderCert
Species the le that contains the OCSP Responder's
signing certicate. View uses this certicate to verify that
the OCSP Responder's responses are genuine.
ocspSendNonce When this property is set to true, a nonce is sent with
OCSP requests to prevent repeated responses.
The default value is false.
ocspCRLFailover When this property is set to true, View uses CRL checking
if OCSP certicate revocation checking fails.
The default value is true.
View Administration
56 VMware, Inc.