Revocation
Chapter
14
Revocation and CRLs
593
After successful authentication, if the server detects only one valid or expired
certificate with matching subject name as that of the one presented for client
authentication, it revokes the certificate. If the server detects more than one valid or
expired certificate with matching subject name, it lists all those certificates. The
user can then either select the certificate to be revoked or revoke all certificates in
the list.
Challenge-Password-Based Revocation
A challenge password is a unique, alphanumeric string that the end user specifies
when requesting a certificate; the user is expected to keep this password
confidential and use it to authenticate to the server when revoking the certificate.
When the server issues the certificate, it associates the password with the
certificate, stores both the certificate and password in its internal database, and
uses them later for authenticating any revocation requests.
In the challenge-password-based revocation method, the server expects the end
user to specify the serial number of the certificate the user wants to revoke and the
challenge password associated with the certificate. The server verifies the
authenticity of a revocation request by mapping the serial number to the list of
certificates in its internal database followed by mapping the challenge password
specified to the one associated with the matching certificate it detects in the internal
database.
Challenge passwords can only be set up with the agent-approved authentication
method. The form associated with the agent-approved authentication is the only
form that contains this capability.
The server revokes the certificate only if the certificate maps successfully to a valid
or expired certificates in its internal database. If the server detects a valid or
expired certificate with a matching serial number and challenge password, it
automatically revokes the certificate.
Certificate Revocation Forms
The end-entity services interface of the Certificate Manager and Registration
Manager includes default HTML forms for both the SSL client authenticated
revocation and challenge-password-based revocation. The forms are accessible
from the Revocation tab. You can view the form that enables SSL client
authenticated revocation by clicking the User Certificate link.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...