The Revocation and Verification of PKI Certificates

Hai Yan Xu · Jisuanji yingyong yanjiu · 2002

With more and more E commerce business companies use digital certificates(a kind of electronical identification signed by Certificate Authority) to ensure the security of on line trade, it triggered another need for security, that is to verify the digital certificates' validity. One of the important procedures in Certificate Authority is to verify whether the user's certificate has been revoked or hold. We always use Certificate Revocation List to save the revoked certificates, and use Lightweight Directory Access Protocol or Online Certificate Status Protocol as verification mechanism. This thesis mainly focused on the Directory Service based on OCSP, but simply introduced the Directory Service based on LDAP, and used an OCSP implementation as an example.

Read the paper · More papers on PaperTik