SSL and Certficate CRL Check


hello

i hope correct forum ask question. reading on x509 v3 standard , cryptography in general when can across an statement said ssl (e.g. ssl hand-shack , subsequent secure channel setup) not bother check crl given certificate, correct?

in other words cdp may published in certificate ssl protocol not retrieve/check crl located cdp check if certificate in question has been revoked or not. not microsoft specific question (rather protocol question e.g. behaviour of ssl protocol). read information respected source (although document little dated)

if case (and perhaps question pki/ssl type forum) can browse web site valid (notafter still within date) certificate (which been revoked ca) unaware of , still setup secure channel web site , perform transactions.

can please enlighten me on please

thanks

aanotheruser__


aanotheruser__

this once true older versions of internet explorer. since ie 7 (i believe) default behavior check revocation. can see in registry: hkey_current_user\software\microsoft\windows\currentversion\internet settings\certificate revocation or can go tools/internet options/advanced tab/[security section]/check server certificate revocation.


mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years.



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file