A system and method is provided for revoking a device. A method includes
receiving a certificate from the device, the certificate including one or
more of fields, at least one of the fields holding a signature,
attempting to verify the signature, receiving a revocation list from a
source, the revocation list identifying one or more data on the
certificate as valid or invalid, the data including at least one of the
fields of the certificate; and if one of one or more signatures
identified unsuccessfully verified and one or more data is identified as
invalid, preventing the transmission of a session key to the device, the
session key being required to establish a secure communication channel.