Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Comment CRL, OCSP and PKIX (Score 3, Informative) 171

Regarding the use of the CRL distribution point extension, a URI that points to a DNS alias can help alleviate the risk.

"OSPF" was likely a botched reference to OCSP (Online Certificate Status Protocol), defined in RFC 2560.

Finally, read the PKIX spec on certificate management, RFC 3280. It will give you a much more detailed understanding of how PKI should work than any vendor docs. This level of understanding is critical if you start playing the role of CA.

If you do your homework, and understand how things work, OpenSSL is an adequate tool.

Slashdot Top Deals

The cost of feathers has risen, even down is up!

Working...