Revocation
Chapter
14
Revocation and CRLs
595
After successful authentication, if the server detects only one valid or expired
certificate with matching subject name as that of the one presented for client
authentication, it revokes the certificate. If the server detects more than one valid or
expired certificate with matching subject name, it lists all those certificates. The
user can then either select the certificate to be revoked or revoke all certificates in
the list.
Challenge-Password-Based Revocation
A challenge password is a unique, alphanumeric string that the end user specifies
when requesting a certificate; the user is expected to keep this password
confidential and use it to authenticate to the server when revoking the certificate.
When the server issues the certificate, it associates the password with the
certificate, stores both the certificate and password in its internal database, and
uses them later for authenticating any revocation requests.
In the challenge-password-based revocation method, the server expects the end
user to specify the serial number of the certificate the user wants to revoke and the
challenge password associated with the certificate. The server verifies the
authenticity of a revocation request by mapping the serial number to the list of
certificates in its internal database followed by mapping the challenge password
specified to the one associated with the matching certificate it detects in the internal
database.
Challenge passwords can only be set up with the agent-approved authentication
method. The form associated with the agent-approved authentication is the only
form that contains this capability.
The server revokes the certificate only if the certificate maps successfully to a valid
or expired certificates in its internal database. If the server detects a valid or
expired certificate with a matching serial number and challenge password, it
automatically revokes the certificate.
Certificate Revocation Forms
The end-entity services interface of the Certificate Manager and Registration
Manager includes default HTML forms for both the SSL client authenticated
revocation and challenge-password-based revocation. The forms are accessible
from the Revocation tab. You can view the form that enables SSL client
authenticated revocation by clicking the User Certificate link.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...