The SSL Handshake
Appendix
K
Introduction to SSL
839
Figure K-2
Authentication of a Client Certificate
An SSL-enabled client goes through these steps to authenticate a server’s identity:
1.
Is today’s date within the validity period?
The client checks the server
certificate’s validity period. If the current date and time are outside of that
range, the authentication process won’t go any further. If the current date and
time are within the certificate’s validity period, the client goes on to Step 2.
2.
Is the issuing CA a trusted CA?
Each SSL-enabled client maintains a list of
trusted CA certificates, represented by the shaded area on the right side of
Figure K-3. This list determines which server certificates the client will accept.
If the distinguished name (DN) of the issuing CA matches the DN of a CA on
the client’s list of trusted CAs, the answer to this question is yes, and the client
goes on to Step 3. If the issuing CA is not on the list, the server will not be
authenticated unless the client can verify a certificate chain ending in a CA that
is on the list.
3.
Does the issuing CA’s public key validate the issuer’s digital signature?
The
client uses the public key from the CA’s certificate (which it found in its list of
trusted CAs in step 2) to validate the CA’s digital signature on the server
certificate being presented. If the information in the server certificate has
changed since it was signed by the CA or if the CA certificate’s public key
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...