Claims
- 1. A method of retrieving CRL information, said method comprising:
receiving a list of one or more servers where the CRL information is stored, the servers each having an identifier; determining which of the servers to contact based on the identifier; and selecting an access method to use to retrieve the CRL information based on the determined server identifier.
- 2. The method as described in claim 1 wherein the access methods are selected from a group consisting of FTP, LDAP, and HTTP.
- 3. The method as described in claim 1 wherein the list of servers is retrieved from a digital certificate corresponding to a remote computer system.
- 4. The method as described in claim 1 wherein the determining further includes:
comparing the identifiers corresponding to the servers with a current domain address; and selecting one of the servers in response to the server's identifier matching the current domain address.
- 5. The method as described in claim 4 further comprising:
selecting a fast access method in response to selecting the server with the identifier matching the current domain address.
- 6. The method as described in claim 4 further comprising:
selecting one of the servers in response to the comparing not finding any server identifiers matching the current domain address; and selecting a secure access method in response to the comparing not finding any server identifiers matching the current domain address.
- 7. The method as described in claim 1 further comprising
retrieving the CRL information from the determined server using the selected access method.
- 8. An information handling system comprising:
one or more processors; a memory accessible by the processors; a nonvolatile storage accessible by the processors; a network interface connecting the information handling system to a computer network; and a CRL retrieval tool for retrieving CRL information, the CRL retrieval tool including: means for receiving a list of one or more servers where the CRL information is stored, the servers each having an identifier; means for determining which of the servers to contact based on the identifier; and means for selecting an access method to use to retrieve the CRL information based on the determined server identifier.
- 9. The information handling system as described in claim 8 wherein the access methods are selected from a group consisting of FTP, LDAP, and HTTP.
- 10. The information handling system as described in claim 8 wherein the means for determining further includes:
means for comparing the identifiers corresponding to the servers with a current domain address; and means for selecting one of the servers in response to the server's identifier matching the current domain address.
- 11. The information handling system as described in claim 10 further comprising:
means for selecting a fast access method in response to selecting the server with the identifier matching the current domain address.
- 12. The information handling system as described in claim 10 further comprising:
means for selecting one of the servers in response to the comparing not finding any server identifiers matching the current domain address; and means for selecting a secure access method in response to the comparing not finding any server identifiers matching the current domain address.
- 13. The information handling system as described in claim 8 further comprising
means for retrieving the CRL information from the determined server using the selected access method.
- 14. A computer program product stored on a computer operable medium for retrieving CRL information, said computer program product comprising:
means for receiving a list of one or more servers where the CRL information is stored, the servers each having an identifier; means for determining which of the servers to contact based on the identifier; and means for selecting an access method to use to retrieve the CRL information based on the determined server identifier.
- 15. The computer program product as described in claim 14 wherein the access methods are selected from a group consisting of FTP, LDAP, and HTTP.
- 16. The computer program product as described in claim 14 wherein the list of servers is retrieved from a digital certificate corresponding to a remote computer system.
- 17. The computer program product as described in claim 14 wherein the means for determining further includes:
means for comparing the identifiers corresponding to the servers with a current domain address; and means for selecting one of the servers in response to the server's identifier matching the current domain address.
- 18. The computer program product as described in claim 17 further comprising:
means for selecting a fast access method in response to selecting the server with the identifier matching the current domain address.
- 19. The computer program product as described in claim 17 further comprising:
means for selecting one of the servers in response to the comparing not finding any server identifiers matching the current domain address; and means for selecting a secure access method in response to the comparing not finding any server identifiers matching the current domain address.
- 20. The computer program product as described in claim 14 further comprising
means for retrieving the CRL information from the determined server using the selected access method.
RELATED APPLICATIONS
[0001] This application is related to the following copending U.S. Patent Applications filed on the same day as the present application and each assigned to the IBM Corporation: “System and Method for Selectively Confirming Digital Certificates in a Virtual Private Network,” (Docket No. AUS9-2000-0924-US1), by Fiveash, Genty, and Wilson System and Method for Multiple Virtual Private Network Authentication Schemes (Docket No. AUS9-2000-0936-US1), by D'Sa, Fiveash, Genty, Venkataraman, and Wilson.