Thin Clients White Papers

A General, Flexible Approach to Certificate Revocation

Overview Since public key certificates have a relatively long lifetime, the information they contain can become invalidated during their lifetime with a significant probability. Therefore, checking certificate revocation information is necessary. “Is there a single method of providing certificate revocation information that solves all of the perceived problems with X.509 v1 CRLs?” There is framework that allows CRLs to be small, to provide timely information when needed, to scale and to be flexible. It also has the advantage that it can be engineered at the outset to provide a reliable service meeting certain space, timeliness and scale requirements and can be modified later if these requirements change. This framework is based on established standards and requires only the definition of one additional certificate extension and one additional CRL extension. We believe that there is no need to define new structures, protocols, and trusted third parties to provide small,timely and scalable revocation information. These objectives can be met with minor additions to existing standards.

Further White Paper Details
PublisherEntrust Technologies File FormatPDF, requires Acrobat Rdr 5
Date PublishedJune 1998 Downloads21
FormatWhite Papers   
Topics

Quick Sitemap Links: