Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Checking for certificate revocation



I need to determine that a certificate is valid and has not been revoked.

No matter what settings I make in the Keychain preferences, I never see any
attempt by the Mac to verify that the certificate has not been revoked.  I
am tracing network activity, and expect the Mac to use OCSP or CRL to check
the certificate.

In my own software, I am using SecTrustEvaluate to check the certificate.
This function always succeeds with kSecTrustResultProceed.

Is a CRL cached?  Is there a way to remove the cached CRL to force the Mac
to retrieve one?

Paul Nelson
Thursby Software Systems, Inc.


 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Apple-cdsa mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/apple-cdsa/email@hidden

This email sent to email@hidden



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.