RFC 2559:Internet X.509 Public Key Infrastructure ...
RFC-Ref

certificate


Click on the red underlined text to get to the source

... profile of that protocol for use within the IPKI and updates encodings for certificates and revocation lists from RFC 1778hist(-> 3494) ...


... X.509 PKI information, including certificates and CRLs from a repository. This specification also addresses ...


... Certification Authorities (CA) ...


... requirement to retrieve PKI information (a certificate, CRL, or other information of interest) from an entry in the repository, where the retrieving entity ...
... delete and modify PKI information information (a certificate, CRL, or other information of interest)in the repository. This is termed "repository modify". ...


... subject or issuer name of a certificate, requires a subset of the following three LDAP operations: ...
... permissions. The application/relying party may need to select an appropriate value to be used. Also note that retrieval of a certificate from a named entry does not guarantee that the certificate will include that same Distinguished Name ...
... certificate from a named entry does not guarantee that the certificate will include that same Distinguished Name (DN) and in ...
... some cases the subject DN in the certificate may be NULL. ...


... To search, using arbitrary criteria, for an entry in a repository containing a certificate, CRL, or other information of interest, requires a subset of the following three LDAP operations ...


... elements are for version 1 certificates and version 1 revocation ...
... revocation lists. Since this specification uses version 3 certificates and version 2 revocation ...
... DER-encoding of the certificate and uses that encoding as the value of the userCertificate attribute in the LDAP ...
... Note that certificates and revocation lists will be transferred using this mechanism rather than the string encodings ...


... PKI service (certificates and CRLs) are both digitally signed pieces of information, additional integrity service ...
... attacker replaces valid certificates with bogus ones. ...



Google
Web
RFC-Ref