pkix-1----Page:6
1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  16  17  18 

Certificate Agility Issues
Implicit assumption that certificate status mechanisms use consistent cryptography
This precludes transitioning to new algorithms
No direct support for multi-alg status mechanisms
If two CRLs are available, client has to download both and parse the CRLs in turn until one with an acceptable signature alg is found
If multiple OCSP servers are available, client doesn’t know which to contact
PPT Version