<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr">Hi,<div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/SP3/PKIX+and+StaticPKIX+TrustEngines">https://wiki.shibboleth.net/confluence/display/SP3/PKIX+and+StaticPKIX+TrustEngines</a>  <br></div><div>above is the documentation i found which i believe is stating i need to use PKIX (also known as dynamic pkix) or StaticPKIX in order to make use of the anchored trust model. </div><div>what's missing is only StaticPKIX has an explicitly listed attribute for CRL revocation check.  (<span style="color:rgb(23,43,77);font-family:SFMono-Medium,"SF Mono","Segoe UI Mono","Roboto Mono","Ubuntu Mono",Menlo,Courier,monospace;font-size:14px">checkRevocation fullchain)</span></div><div>1.) Does this mean CRL is automatically done on the dynamic PKIX?</div><div>2.) what about checking expiration?</div><div>3.) does this mean all I would need to do for an Anchor verification is set the trust engine like so:<br></div><div><div>         <TrustEngine type="PKIX"></div></div><div>and my requirement for Validating signatures using Anchored certificate trust model would be complete?</div><div><br></div><div>Also, </div><div><a href="https://wiki.shibboleth.net/confluence/display/SP3/TrustEngine">https://wiki.shibboleth.net/confluence/display/SP3/TrustEngine</a> </div><div>above lists 3 types of trust engines, not 4 but the text says there are 4.<br></div><div><br></div><div>Thank you,</div><div>Irfan</div><div><br></div></div></div></div></div>