go to  ForumEasy.com   
JavaPro
Home » Archive » Message


[Email To Friend][View in Live Context][prev topic « prev post | next post » next topic]
  What's the order then?
 
Subject: What's the order then?
Author: X509
In response to: How many ways are there to do certificate revocation checking ?
Posted on: 07/01/2010 02:49:19 PM

The three ways can be activated at the same time for certificate checking, but the process follows the order:

OCSP --> CRLDP --> CRL File

If the incoming certificate passes OCSP checkpoint, then CRLDP, and CRL File at last.


 

> On 06/25/2010 10:16:23 PM X509 wrote:


There are three ways to do certificate revocation checking:

1) Statically by CRL ( (Certificate Revocation List) files which are typically in local storage;

2) Dynamically by CRL Distribution Point (CRLDP) which is inside the target certificate as a URL typically pointing to the issuer's CA CRL repository;

3) Dynamically by OCSP to any server which provides Certificate Revocation Checking service.





References:

 


 
Powered by ForumEasy © 2002-2022, All Rights Reserved. | Privacy Policy | Terms of Use
 
Get your own forum today. It's easy and free.