A method of managing certificates in a communication system having a
certifying authority and a directory. Preferably, the method begins by
having the certifying authority generate certificates by digitally
signing a given piece of data. At a later point time, the certifying
authority may produce a string that proves whether a particular
certificate is currently valid without also proving the validity of at
least some other certificates. The technique obviates use of
certification revocation lists communicated between the certifying
authority and the directory.