Answered step by step
Verified Expert Solution
Question
1 Approved Answer
We discussed certification revocation list in class trust intermediaries . Instead of keeping a CRL ( that is , a bad - list ) which
We discussed certification revocation list in class trust intermediaries Instead of keeping a CRL that is a badlist which contains all the invalid certificates, the system can also be implemented by letting the server keep a goodlist, that is a list containing all the valid certificates.
However, these two approaches are implemented differently. A badlist only need to contain the serial numbers of all the invalid certificate, but a goodlist needs to include both the serial number and the hash of the complete certificate remind that a certificate contains serial number, subject name, issuer, and many other information, as I have shown in class
Why is it important for a goodlist to keep hashes of the valid certificates, why it is not enough to include the serial number only?
Hint: think the example of credit card, if a bank wants to maintain a list of valid credit cards, is it sufficient to keep the card number only?
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started