Revoking Certificates
469
B.5.4. Revoking Certificates
Like a driver's license, a certificate specifies a period of time during which it is valid. Attempts to use a
certificate for authentication before or after its validity period will fail. Managing certificate expirations is
an essential part of the certificate management strategy. For example, an administrator may wish to be
notified automatically when a certificate is about to expire so that an appropriate replacement process
can be completed without disrupting the system operation.
Additionally, it may be necessary to revoke a certificate before it has expired, such as when an
employee leaves a company or moves to a new job in a different unit within the company.
Certificate revocation can be handled in several different ways. Servers can be configured so that the
authentication process checks the directory for the presence of the certificate being presented. When
an administrator revokes a certificate, the certificate can be automatically removed from the directory,
and subsequent authentication attempts with that certificate will fail, even though the certificate
remains valid in every other respect. Alternatively, a list of revoked certificates, a certificate revocation
list (CRL), can be published to the directory at regular intervals. The CRL can be checked as part of
the authentication process. The issuing CA can also be checked directly each time a certificate is
presented for authentication. This procedure is sometimes called real-time status checking.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...