Determining access includes determining if particular credentials/proofs
indicate that access is allowed, determining if there is additional data
associated with the credentials/proofs, wherein the additional data is
separate from the credentials/proofs, and, if the particular
credentials/proofs indicate that access is allowed and if there is
additional data associated with the particular credentials/proofs, then
deciding whether to deny access according to information provided by the
additional data. The credentials/proofs may be in one part or in separate
parts. There may be a first administration entity that generates the
credentials and other administration entities that generate proofs. The
first administration entity may also generate proofs or may not generate
proofs. The credentials may correspond to a digital certificate that
includes a final value that is a result of applying a one way function to
a first one of the proofs.