英語 での Revocation information の使用例とその 日本語 への翻訳
{-}
-
Colloquial
-
Ecclesiastic
-
Computer
-
Programming
Revocation information for the security certificate for the site is not available.
If the bit 0x40 is set,then this means that the revocation information is sensitive.
If revocation information is untimely or unavailable, the assurance associated with the binding is clearly reduced.
An OCSP responder may be queried for revocation information by delegated path validation(DPV) servers.
Additionally, the AIA may specify the location of an OCSP[RFC2560]responder that is able to provide revocation information for the certificate.
The availability and freshness of revocation information will affect the degree of assurance that should be placed in a certificate.
If the DistributionPoint omits the reasons field,the CRL MUST include revocation information for all reasons.
Justification: The revocation information for a given certificate should be produced by the PKI that issues the certificate.
That is, the complete CRL contains(at a minimum) all the revocation information held by the referenced base CRL.
If a delta CRL and a complete CRL that cover the same scope are issued at the same time,they MUST have the same CRL number and provide the same revocation information.
The availability and freshness of revocation information affects the degree of assurance that ought to be placed in a certificate.
The use of delta-CRLs can significantlyimprove processing time for applications which store revocation information in a format other than the CRL structure.
Delta CRLs contain updates to revocation information previously distributed, rather than all the information that would appear in a complete CRL.
If a CRLDP extension appears within a certificate, the CRL(s) to which the CRLDP referare generally the CRLs that would contain revocation information for the certificate.
Applications which store revocation information in a format other than the CRL structure can add new revocation information to the local database without reprocessing information. .
That is, the combination of the delta CRL andan acceptable complete CRL MUST provide the same revocation information as the simultaneously issued complete CRL.
CAs SHOULD take extra care when making revocation information available only through CRLs that contain critical extensions, particularly if support for those extensions is not mandated by this profile.
Conforming applications that support CRLs are REQUIRED to process both version 1 andversion 2 complete CRLs that provide revocation information for all certificates issued by one CA.
The attrRevReq specifies minimum requirements for revocation information, obtained through CRLs and/or OCSP responses, to be used in checking the revocation status of Attribute Certificates, if any are present.
OCSP may be used tosatisfy some of the operational requirements of providing more timely revocation information than is possible with CRLs and may also be used to obtain additional status information. .
For example, if revocation information is supplied using a combination of delta CRLs and full CRLs, and the delta CRLs are issued more frequently than the full CRLs, then relying parties that cannot handle the critical extensions related to delta CRL processing will notbe able to obtain the most recent revocation information.
The tstrRevReq specifies minimum requirements for revocation information, obtained through CRLs and/or OCSP responses, to be used in checking the revocation status of the time-stamp that must be present in the ES-T.
In a revocation request information about the license on the computer without Internet connection is stored.
As a result,it is better to delay retrieving CRLs or other revocation status information until a complete path has been found.
Logic for retrieving the necessary certificates(and CRLs and/or other revocation status information if the path is to be validated) from the available sources.
The revocation status information forming the ES with Complete validation data must not be collected and used to validate the electronic signature until after this caution period.
This means that the security is dependent upon the security of the CA that has issued the TSU certificate for both issuing the certificate andproviding accurate revocation status information for that certificate.