Revoking Certificates
505
B.5.4. Revoking Certificates
Like a driver's license, a certificate specifies a period of time during which it is valid. Attempts to use a
certificate for authentication before or after its validity period will fail. Managing certificate expirations is
an essential part of the certificate management strategy. For example, an administrator may wish to be
notified automatically when a certificate is about to expire so that an appropriate replacement process
can be completed without disrupting the system operation.
Additionally, it may be necessary to revoke a certificate before it has expired, such as when an
employee leaves a company or moves to a new job in a different unit within the company.
Certificate revocation can be handled in several different ways. Servers can be configured so that the
authentication process checks the directory for the presence of the certificate being presented. When
an administrator revokes a certificate, the certificate can be automatically removed from the directory,
and subsequent authentication attempts with that certificate will fail, even though the certificate
remains valid in every other respect. Alternatively, a list of revoked certificates, a certificate revocation
list (CRL), can be published to the directory at regular intervals. The CRL can be checked as part of
the authentication process. The issuing CA can also be checked directly each time a certificate is
presented for authentication. This procedure is sometimes called real-time status checking.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...