CRLManager Class
Properties Methods Events Configuration Settings Errors
The CRLManager class supports the importing, exporting, and validation of Certificate Revocation Lists (CRLs).
Syntax
SecureBlackboxCRLManager
SecureBlackboxCRLManagerSwift
Remarks
CRLs store information about revoked certificates, i.e., certificates that have been identified as invalid for any number of reasons by the issuing certificate authority (CA). CRLs identify certificates by their serial numbers. Therefore, by knowing the certificate's SerialNumber, its validity status can be checked against a CRL.
Each CRL corresponds to one issuing point, and each Certificate Authority (CA) certificate can have a corresponding CRL which contains information about the certificates signed with this CA certificate.
CAs are not required to issue CRLs if other revocation or certificate status mechanisms are provided. Each CRL must contain the date by which the next CRL will be issued. This date is specified by the NextUpdate field.
Property List
The following is the full list of the properties of the class with short descriptions. Click on the links for further details.
- CACertBytes | Returns raw certificate data in DER format. |
- CACertHandle | Allows to get or set a 'handle', a unique identifier of the underlying property object. |
- CRLBytes | Returns raw CRL data in DER format. |
- CRLCAKeyID | A unique identifier (fingerprint) of the CA certificate's private key, if present in the CRL. |
- CRLEntryCount | Returns the number of certificate status entries in the CRL. |
- CRLHandle | Allows to get or set a 'handle', a unique identifier of the underlying property object. |
- CRLIssuer | The common name of the CRL issuer (CA), typically a company name. |
- CRLIssuerRDN | A collection of information, in the form of [OID, Value] pairs, uniquely identifying the CRL issuer. |
- CRLLocation | The URL that the CRL was downloaded from. |
- CRLNextUpdate | The planned time and date of the next version of this CRL to be published. |
- CRLSigAlgorithm | The public key algorithm that was used by the CA to sign this CRL. |
- CRLTBS | The to-be-signed part of the CRL (the CRL without the signature part). |
- CRLThisUpdate | The date and time at which this version of the CRL was published. |
- entryCount | The number of items in the CRL. |
- CRLEntryInfoCertStatus | Returns the status of the certificate. |
- CRLEntryInfoHandle | Allows to get or set a 'handle', a unique identifier of the underlying property object. |
- CRLEntryInfoRevocationDate | The time and date when the certificate gets revoked or cancelled. |
- CRLEntryInfoRevocationReason | Specifies the reason for certificate revocation. |
- CRLEntryInfoSerialNumber | The certificate serial number. |
- externalCryptoCustomParams | Custom parameters to be passed to the signing service (uninterpreted). |
- externalCryptoData | Additional data to be included in the async state and mirrored back by the requestor. |
- externalCryptoExternalHashCalculation | Specifies whether the message hash is to be calculated at the external endpoint. |
- externalCryptoHashAlgorithm | Specifies the request's signature hash algorithm. |
- externalCryptoKeyID | The ID of the pre-shared key used for DC request authentication. |
- externalCryptoKeySecret | The pre-shared key used for DC request authentication. |
- externalCryptoMethod | Specifies the asynchronous signing method. |
- externalCryptoMode | Specifies the external cryptography mode. |
- externalCryptoPublicKeyAlgorithm | Provide public key algorithm here if the certificate is not available on the pre-signing stage. |
Method List
The following is the full list of the methods of the class with short descriptions. Click on the links for further details.
- add | Adds a new revoked certificate entry. |
- clear | Empties the CRL. |
- config | Sets or retrieves a configuration setting. |
- download | Downloads a CRL from the specified location. |
- getCertEntryIndex | Returns the index of the CRL item by the certificate's serial number. |
- load | Loads a CRL from a byte array. |
- loadFromFile | Loads a CRL from a file. |
- remove | Removes the specified entry from the CRL. |
- save | Saves the CRL to a byte array. |
- saveToFile | Saves the CRL to a file. |
- selectEntry | Fetches revocation information about the selected certificate from the CRL. |
- validate | Validates the CRL signature. |
Event List
The following is the full list of the events fired by the class with short descriptions. Click on the links for further details.
- onError | Information about errors during CRL management. |
- onExternalSign | Handles remote or external signing initiated by the SignExternal method or other source. |
- onNotification | This event notifies the application about an underlying control flow event. |
Configuration Settings
The following is a list of configuration settings for the class with short descriptions. Click on the links for further details.
CheckKeyIntegrityBeforeUse | Enables or disable private key integrity check before use. |
CookieCaching | Specifies whether a cookie cache should be used for HTTP(S) transports. |
Cookies | Gets or sets local cookies for the class (supported for HTTPClient, RESTClient and SOAPClient only). |
DefDeriveKeyIterations | Specifies the default key derivation algorithm iteration count. |
EnableClientSideSSLFFDHE | Enables or disables finite field DHE key exchange support in TLS clients. |
GlobalCookies | Gets or sets global cookies for all the HTTP transports. |
HttpUserAgent | Specifies the user agent name to be used by all HTTP clients. |
LogDestination | Specifies the debug log destination. |
LogDetails | Specifies the debug log details to dump. |
LogFile | Specifies the debug log filename. |
LogFilters | Specifies the debug log filters. |
LogFlushMode | Specifies the log flush mode. |
LogLevel | Specifies the debug log level. |
LogMaxEventCount | Specifies the maximum number of events to cache before further action is taken. |
LogRotationMode | Specifies the log rotation mode. |
MaxASN1BufferLength | Specifies the maximal allowed length for ASN.1 primitive tag data. |
MaxASN1TreeDepth | Specifies the maximal depth for processed ASN.1 trees. |
OCSPHashAlgorithm | Specifies the hash algorithm to be used to identify certificates in OCSP requests. |
UseOwnDNSResolver | Specifies whether the client classes should use own DNS resolver. |
UseSharedSystemStorages | Specifies whether the validation engine should use a global per-process copy of the system certificate stores. |
UseSystemOAEPAndPSS | Enforces or disables the use of system-driven RSA OAEP and PSS computations. |
UseSystemRandom | Enables or disables the use of the OS PRNG. |