CRLs are lists that are published either regularly or irregularly to help to report the latest revocation status of certs. The list contains of serial numbers of certs that have been revocated and reseaons for it, if there is any. If you have interest, you can go to IETF's pkix working group to see corresponding RFCs. Hope can be of help. Hazel > hello all, > > I have read a few literatures, but still I can't figure out what > certificate revocation list (CRL) is all about? > Is there anybody who can give me an explaination, or show me good stuffs > to read? > > TIA > > -donny- > > ______________________________________________________________________ > OpenSSL Project http://www.openssl.org > User Support Mailing List [EMAIL PROTECTED] > Automated List Manager [EMAIL PROTECTED] > ______________________________________________ Miss Yuhang Gao CERNET Regional Network Center, Dept. of Computer Sci. & Eng. Southeast University, Nanjing 210096, P.R.China Tel: +86-25-3794342 ext 211 Fax: +86-25-3614842 ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]