R2 features and documentation?
"Zolfonoon, Riaz" <[email protected]> Wed, 3 Feb 1999 12:18:55 -0500
| Newsgroups | gmane.ietf.pfl |
|---|---|
| Message-ID | <D104150098E6D111B7830000F8D90AE84D7445@exna02.securitydynamics.com> |
Hi,
I've installed R2 on NT. Here are few questions:
1) When I start Jonahee, most of the menu options seem to be disabled.
I've tried Actions->CreateCertRequestre. It is expecting a preregistration
option file. What is this file and what's its format?
2) What is the Action->Initialize for? Is it supposed to initialize my
virtual smart card? Or initialize the GUI tool? It does not seem to do
anything.
3) If I click on some buttons, say Help, Java runtime (jre.exe) seems
to go into an infinite loop and consume almost 100% of CPU. Has anyone seen
this problem?
4) Is there any documentation that describes the features, supported
algorithms, the GUI usage, etc.(or is the source code the ultimate spec:-))?
I have seen a paper on IBM site that describes the planned features for R1
and R2. I have enclosed extracts form this paper. Could someone from Jonah
team comment on the status of each feature listed below (implemented in Rx
or will be done later at such date).
Regards,
Riaz
=-=-=-=-=-=-=-=-
from: http://www.ibm.com/security/html/wp_pkix.html
<http://www.ibm.com/security/html/wp_pkix.html> :
The August (snap shot) version will provide the following:
Ability to create client certs extensions (such as
key usage, basic constraints, name
constraints (permitted subtree only), key IDs,
policies)
Ability to read certs
.......
...
December Deliverables
The main areas of functionality supplied within this
release are Certification trust chain handling,
directory technology and access protocol, directory user,
certificate, and CRL schema, revocation
check policy, and CRL issuance policy
Features planned for this release are:
Key refresh (process for instance when certificate
has expired and key has not)
CA key Rollover (process for managing CA key
expiration)
Hierarchical CA (support for Trust hierarchy)
Cross certification (ability to certify non Notes CA)
Additional CRL extension support (e.g. reasons,
invalidity date, etc.)
Ability for client to specify a set of policy
constraints
Create x-key usage (ability to support extensions
that are not listed in the X.509
specifications)
Netscape interoperability