Digital Certificate Operation in a Complex Environment

CRL Certificate Revocation List A list containing every certificate that has been revoked by the Certification Authority (CA) that has not been expired for other reasons. (Ideally, a CA issues a CRL at regular intervals. Besides listing certificates that have been revoked, the CRL states how long it will be valid and where to get the next CRL.) It is likely that this technology is practically flawed as CRLs can become very large, so development is continuinginto real-time certificate validation (e.g. XML Key Management Specification XKMS and the Security Assertions Markup Language - SAML). Seealso OCSP.
