-
33
pages
-
English
-
Documents
Description
CRL Processing RulesSantosh ChokhaniMarch 17 2005Briefing Contents• Historical Timeline• Issues and Resolution• Summary of Recommended Editorial Changes to RFC 3280 and RFC 2560, and X.509• Path Matching Algorithm• Backup Slides2Historical Timeline• DoD PKI motivates development of CRL Processing Rules (1997-98)• Rules submitted to X.509 Editor (1998-99)• X.509 accepted Input as Normative Annex (1999)• RFC 3280 uses the Annex to define CRL Processing Rules (??) (2002)• Issue of some CA products not asserting IDP for partial CRL comes to light (2002)• Three discussion threads on PKIX on the issue of similarity of certificate “Certification Path” and CRL “Certification Path” (2002-04)3Issues and Resolution• What identifies a CA: name only or name + key?• What does absence of IDP mean?• How to ensure a CRL is from a CRL Issuer as intended by the certificate issuing CA?• Should circularity be permitted during revocation status checking?4What identifies A CA• Issue– For certificates and CRL processing logic, is a CA defined by name only or by name and a signing private key/signature verification public key• Resolution– A CA is identified by name alone• Basis– Numerous places in X.509 and RFC 3280– Section 7 of X.509• Recommendation– Add a statement to RFC 3280 that a CA is identified by name5What Does Absence of IDP in a CRL Mean• Issue– What does absence of IDP in a CRL mean for the scope of that CRL• Resolution– Absence ...
-
Publié par
-
Langue
English