Re: Cert Revocation



You can check against a local list or a remote list - the location of the remote list can be found in the CDP (CRL distribution point) extension in the cert - this usually points to a .crl file (e.g. via HTTP).

This document has all the details:
http://www.microsoft.com/technet/prodtechnol/winxppro/support/tshtcrl.mspx

-----
Dominick Baier (http://www.leastprivilege.com)

Developing More Secure Microsoft ASP.NET 2.0 Applications (http://www.microsoft.com/mspress/books/9989.asp)

I see that it is possible in CryptoApi to specify flags requesting
that a certificate chain being checked is also checked for revocation.

I have some high level questions about how this works.

Does CryptoApi check a local revocation list? Does it use OCSP (I
don't think so but I'm just throwing the question out here)?

If it uses a local list, how often do windows systems have their lists
updated, if ever?



.



Relevant Pages

  • Re: match value within any portion of lookup string in range
    ... I have 2 app lists, neither of which I own, no standardized naming convention. ... I'm trying to compare my final list (ApplicationListMaster!C:C) with a list dump from a script which queries all app instances and posts them to a .php page. ... Insurance Safety Data ... CDP - Career Development Planning ...
    (microsoft.public.excel.worksheet.functions)
  • match value within any portion of lookup string in range
    ... I have 2 app lists, neither of which I own, no standardized naming ... Insurance Safety Data ... CDP - Career Development Planning ...
    (microsoft.public.excel.worksheet.functions)
  • RE: match value within any portion of lookup string in range
    ... I have 2 app lists, neither of which I own, no standardized naming ... Insurance Safety Data ... CDP - Career Development Planning ...
    (microsoft.public.excel.worksheet.functions)