Repository Issues

As Chapter 8, "Certificate Revocation," and Chapter 11, "PKI Information Dissemination: Repositories and Other Techniques," discussed, many enterprise domains utilize a ubiquitous on-line repository to allow for the timely and robust dissemination of certificates, certificate revocation information (for example, Certificate Revocation Lists, or CRLs) and any other PKI-related information (for example, policy information). Early PKI deployment experience has demonstrated that this is not without its problems—although these issues are expected to be corrected as the products offered by the vendor community continue to evolve. The purpose of this section is to discuss some of these issues.

Lack of Industry-Accepted Standard

Get Understanding Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.