Talk With an Expert

Securing Certificate Revocation List Infrastructures

Securing Certificate Revocation List Infrastructures (PDF, 1.62MB)Published: 19 Sep, 2001
Created by
Eddie Turkaly

Anyone working within a Public Key Infrastructure (PKI) or an environment that uses client side certificates should be concerned that during authentication the Certificate Revocation Lists (CRL) are consistently & properly verified. Microsoft's Internet Information Server (IIS) 5.0 built-in Certificate Revocation List Infrastructure has been openly questioned from several security professionals and been a part of at least one major security vulnerability. This research takes a closer look at the security issues when implementing a secure CRL infrastructure as well as looking deeply into how secure Microsoft's IIS 5.0 built in Certificate Revocation List Infrastructure is. Then we will explore alternative CRL solutions from Internet Standards, PKI Toolkits and middle-ware products. Finally, this research should provide you with the security awareness ins and outs for implementing a secure CRL infrastructure.