honzeland

          記錄點(diǎn)滴。。。

          常用鏈接

          統(tǒng)計(jì)

          Famous Websites

          Java

          Linux

          P2P

          最新評(píng)論

          SCEP(Simple Certificate Enrollment Protocol)

          1. RFC documents

          2. SCEP operations
          • PKIOperation:      
            • Certificate Enrollment - request: PKCSReq, response: PENDING, FAILURE, SUCCESS
            • Poll for Requester Initial Certificate - request: GetCertInitial, response: same as for PKCSReq
            • Certificate Access - request: GetCert, response: SUCCESS, FAILURE
            • CRL Access - request: GetCRL, response: raw DER encoded CRL
          • Non-PKIOperation: clear HTTP Get
            • Get Certificate Authority Certificate - GetCACert, GetNextCACert, GetCACaps
            • Get Certificate Authority Certificate Chain - GetCACertChain
          3. Request message formats for PKIOperation
          • Common fields in all PKIOperation messages:
            • senderNonce
            • transactionID
            • the SCEP message being transported(SCEP messages) -> encrypted using the public key of the recipient(Enveloped-data)
              -> signed by one of certificates(Signed-data): the requester can generate a self-signed certificate, or the requester can use
              a previously issued certificate, if the RA/CA supports the RENEWAL option.
          • SCEP messages:
            • PKCSReq: PKCS#10
            • GetCertInitial: messages for old versions of scep clients such as Sscep, AutoSscep, and Openscep, are different with draft-18
                     issuerAndSubject ::= SEQUENCE {
                          issuer Name,
                          subject Name
                     }
            • GetCert: an ASN.1 IssuerAndSerialNumber type, as specified in PKCS#7 Section 6.7
            • GetCRL: an ASN.1 IssuerAndSerialNumber type, as defined in PKCS#7 Section 6.7

          posted on 2009-02-17 14:18 honzeland 閱讀(1710) 評(píng)論(2)  編輯  收藏

          評(píng)論

          # re: SCEP(Simple Certificate Enrollment Protocol) 2009-02-18 14:02 Fingki.li

          好久不見你的文章了,呵呵  回復(fù)  更多評(píng)論   

          # re: SCEP(Simple Certificate Enrollment Protocol) 2009-02-18 17:51 honzeland

          以后走頻繁路線  回復(fù)  更多評(píng)論   


          只有注冊(cè)用戶登錄后才能發(fā)表評(píng)論。


          網(wǎng)站導(dǎo)航:
           
          主站蜘蛛池模板: 彰武县| 绿春县| 万荣县| 太和县| 佛山市| 罗江县| 乐亭县| 弥勒县| 保靖县| 突泉县| 西青区| 永平县| 汝南县| 来安县| 太谷县| 天全县| 政和县| 新宾| 九江市| 咸阳市| 连江县| 永顺县| 同心县| 阿鲁科尔沁旗| 石楼县| 唐河县| 加查县| 太白县| 鄯善县| 永寿县| 延长县| 称多县| 阿坝| 永靖县| 黄龙县| 阳谷县| 莱州市| 太湖县| 佛教| 红原县| 武宁县|