Revoked Certificates
Consult Revoked Certificates
ACEDICOM will publish a new CRL in the repository at 24 hour intervals maximum, even though no modifications have taken place in the same (changes in certificate status) during said period.
Verification of the revocations is obligatory for each use of public identity certificates. The ordinary procedure for verification of the validity of a certificate will be by query to the ACEDICOM Validation Services, which will indicate the status of the certificate by OCSP protocol.
ACEDICOM also provides for publication of CRLs.
Certificate Status Verification Services
Operating Features
For certificate validation, ACEDICOM has online Validation Services, in addition to the publication of CRLs, which provide information on the status of certificates issued by the ACEDICOM certification hierarchy. This is an online validation service (Validation Authority, VA) that implements the Online Certificate Status Protocol according to RFC 2560. By the use of this protocol, the current status of an electronic certificate is determined without requiring the CRLs. An OCSP client sends a query about the status of the certificate to the VA, which, after consulting its DB, gives a response on the certificate status via HTTP.
To make use of the online Validation Service it is the responsibility of the Third Acceptor to have an OCSP Client in compliance with RFC 2560.
The URLs of the OCSP service are:
- OCSP acedicom01: http://ocsp.acedicom.edicomgroup.com/acedicom01
- OCSP acedicom02: http://ocsp.acedicom.edicomgroup.com/acedicom02
The Certificate of the OCSP service are:
The URLs of the CRLs are:
- Root CRL: http://acedicom.edicomgroup.com/rootca.crl
- CRL acedicom01: http://acedicom.edicomgroup.com/acedicom01.crl
- CRL acedicom02: http://acedicom.edicomgroup.com/acedicom02.crl
Service Availability
The CRLs and certificate status online query systems are available 24 hours a day, 7 days a week.