Skip to main content

Securing Certificate Revocation List Infrastructures

Anyone working within a Public Key Infrastructure (PKI) or an environment that uses client side certificates should be concerned that during authentication the Certificate Revocation Lists (CRL) are consistently & properly verified. Microsoft's Internet Information Server (IIS) 5.0 built-in Certificate Revocation List Infrastructure has been openly questioned from several security professionals and been a part of at least one major security vulnerability. This research takes a closer look at the security issues when implementing a secure CRL infrastructure as well as looking deeply into how secure Microsoft's IIS 5.0 built in Certificate Revocation List Infrastructure is. Then we will explore alternative CRL solutions from Internet Standards, PKI Toolkits and middle-ware products. Finally, this research should provide you with the security awareness ins and outs for implementing a secure CRL infrastructure.

748 (PDF, 1.62MB)

19 Sep 2001
ByEddie Turkaly
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.