In general, RFC 3280 contains almost complete instructions for performing validation, but these instructions are very nontrivial. In addition, you will need to read the RFC 2560 (OCSP) and implement the OCSP client.
For most tasks you will find our TElX509CertificateValidator component perfectly suited. It checks certificate paths, CRL revocation, and OCSP paths (and also verifies CRL validity and OCSP responses). It is flexible enough and powerful enough and allows you to perform additional, deeper checks at every step. Also, this component can work with both Windows certificate stores and any other certificates, certificate chains, and stores that can be stored in files or in memory.
Eugene Mayevski 'Allied Bits
source share