WebApp Sec mailing list archives

Re: How to perform SSL certificate validation ?


From: paseidon76 () yahoo com
Date: 11 Jul 2006 14:27:56 -0000

If you are using Java then IAIK library provides excellent support for everything you need to do with certificate 
validation.
http://jcewww.iaik.tu-graz.ac.at/

In addition to building a chain to a trusted root CA (which will need a trusted root store and all the intermediate CA 
certificates) you may want to verify if the CA's cert was revoked by the root. This can be done by OCSP request/ reply. 

-------------------------------------------------------------------------
Sponsored by: Watchfire

Cross-Site Scripting (XSS) is one of the most common application-level 
attacks that hackers use to sneak into web applications today. This 
whitepaper will discuss how traditional CSS attacks are performed, how to 
secure your site against these attacks and check if your site is protected. 
Cross-Site Scripting Explained - Download this whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008Vmr
--------------------------------------------------------------------------


Current thread: