资 源 简 介
PathFinder is designed to provide a mechanism for any program to perform
RFC3280-compliant path validation of X509 certificates, even when some of the intermediate certificates are not present on the local machine. By design, Pathfinder automatically downloads any such certificates from the Internet as needed using the AIA and CRL distribution point extensions of the certificates it is processing. It has the ability to do revocation status checking either using CRL or OCSP, or both. And, given the recent vulnerabilities that have rendered the MD5 algorithm highly suspect, it allows the administrator to choose to not validate certificates using that algorithm anywhere in the trust path.
For the convenience of those using OpenSSL or NSS (Netscape Security Services), two libraries containing a Pathfinder callback suitable for use with an SSL connection are provided with the main distribution.
It does its best to pass
文 件 列 表
pathfinder-1.1.7
pathvalidator.h
pathserver.h
LICENSE
pathfinder.cc
pathfinderd-dbus.conf
pathfinder.h
CMakeLists.txt
AUTHORS
pathfinder-openssl-uninstalled.pc.in
version.h.in
.gitignore
pathclient.cc
pathclient.3
pathverify.3
pathverify.cc
openssltest.cc
README
t
testdata
pathfinderd.8
pathfinder-nss-uninstalled.pc.in
libpathfinder
pathfinderd.ini.sample
pathfinderd.cc
downloader.cc
revocationfinder.h
pathfinder-nss.pc.in
util.h
pathfinder-openssl.pc.in
downloader.h
util.cc
pathfinder-dbus.conf.sample
revocationfinder.cc
pathvalidator.cc
x509path
nsstest.cc
pathserver.cc