A method for distributively managing the CRL in a certifying system to certify
the validity of a subscriber in an open communications network such as Internet,
includes the steps of registering the certificate policy statement for the CRL
by determining the distribution interval of the CRL; setting the structure of the
certificate of the subscriber to issue the certificate according to the registered
certificate policy statement; attesting the certificate by applying the distribution
point mechanism according to the distribution interval to the CRL; and revoking
the certificate by using the distribution points to revise the CRL displayed.