Netscape Certificate Management System (CMS) provides methods for revoking
certificates and for producing lists of revoked certificates, called certificate
revocation lists (CRLs). This chapter describes the methods for revoking a
certificate, describes CMC Revocation, and provides details about CRLs and
setting up CRLs.
This chapter contains the following sections:
•
Revocation
•
CMCRevocation
•
About CRLs
•
Setting Up the Issuance of CRLs
•
CRL Extension Reference
Revocation
Certificates can be revoked by an end user (the original owner of the certificate), a
server administrator, or by a Certificate Manager agent. End users can revoke
certificates by using the Revocation form provided in the end-entity services
interface. Agents can revoke end-entity certificates by using the appropriate form
in the Agent Services interface. Certificate-based (SSL client authentication) or
challenge-password-based authentication is required in both cases.
•
An end user can revoke only those certificates that contain the same subject
name as in the certificate presented for authentication; if using a challenge
password, the user can revoke only the certificate that is associated with that
password. After successful authentication, the server lists the certificates
belonging to the end user. The end user can then select the certificate to be
Revocation and CRLs
Chapter 14
593
Need help?
Do you have a question about the NETSCAPE MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR and is the answer not in the manual?