This chapter describes and illustrates the use of Certificate, Key, and Trust Services functions to evaluate the trust of a certificate, determine the cause of a trust failure, and recover from a trust failure.
The sequence of operations illustrated in this chapter is:
Find a certificate in a keychain.
Obtain a policy object for the policy used in evaluation of the certificate.
Validate the certificate and evaluate whether it can be trusted as specified by the policy.
Test for a recoverable trust error.
Determine whether the trust error is due to an expired certificate.
Change the evaluation criteria to ignore expired certificates.
Reevaluate the certificate.
“Chapter 2, Certificate, Key, and Trust Services Concepts,” provides an introduction to the concepts and terminology of Certificate, Key, and Trust Services. For detailed information about all Certificate, Key, and Trust Services functions, see Certificate, Key, and Trust Services Reference.
Finding a Certificate on the Keychain
Obtaining a Policy Object
Evaluating Trust
Recovering From a Trust Failure
Last updated: 2004-06-28