Latest Additions

September 08, 2010
Put Your URL Everywhere
You should be advertising your Web site everywhere Wherever you put your telephone number put your...
September 08, 2010
Two Common Web Design Myths
If your site has been around for a while you d probably have been visited by the Web Design Police...

Site Search

Certificate Revocation List (CRL)

CRL is one of two common methods when using a public key infrastructure for maintaining access to servers in a network. The other, newer method, which has superseded CRL in some cases, is Online Certificate Status Protocol (OCSP).

The CRL is exactly what its name implies: a list of subscribers paired with digital certificate status. The list enumerates revoked certificates along with the reason(s) for revocation. The dates of certificate issue, and the entities that issued them, are also included. In addition, each list contains a proposed date for the next release. When a potential user attempts to access a server, the server allows or denies access based on the CRL entry for that particular user.

The main limitation of CRL is the fact that updates must be frequently downloaded to keep the list current. OCSP overcomes this limitation by checking certificate status in real time.
This topic was last modified on 03-31-2010 and has had 29 hits. These are popular related words: