2.2.2.20 ValidateCert
The ValidateCert command is used by the client to validate a certificate that has been received via an S/MIME mail.
To validate a certificate, the server MUST verify that the certificate has not expired and has not been revoked. The server MUST walk up the certificate chain, verifying that each intermediate CA certificate has not expired and has not been revoked and that the root certificate is a trusted certification authority (CA) (1). Certificate validation is particularly important for verifying signatures (for example, on S/MIME signed mail).
The ValidateCert namespace is the primary namespace for this section. Elements referenced in this section that are not defined in the ValidateCert namespace use the namespace prefixes defined in section 2.2.1.
The following table lists the elements that are used in ValidateCert command requests and responses.
|
Element name |
Scope |
Reference |
|
ValidateCert |
Request and Response |
section 2.2.3.179 |
|
CertificateChain |
Request |
section 2.2.3.20 |
|
Certificate |
Request and Response |
section 2.2.3.19.2 |
|
Certificates |
Request |
section 2.2.3.23.2 |
|
CheckCRL |
Request |
section 2.2.3.26 |
|
Status |
Response |
section 2.2.3.162.17 |