Revocation in this case must be based on the cryptographic fingerprint of the certificate, and the mechanism that provides this functionality is a certificate revocation list (CRL).
在此情况下,撤销必须基于该证书的加密指纹,而提供此功能的机制就是证书撤销列表(CRL)。
Figure 1 shows the basic process of creating a certificate using a ca and distributing it, in this case, to perform server authentication with SSL.
图1中显示了使用CA创建证书和分发的基本流程,对于本例,用于通过SSL执行服务器身份验证。
Also, it is customary to revoke a certificate only in the case that it is compromised and not simply as a means to revoke privileges.
另外,按照惯例仅在证书遭到破坏时才撤销它,并不仅用作撤销权限的手段。
应用推荐