v1.6 Certificate Management Library
"Pawling, John" <[email protected]>
| Newsgroups | gmane.ietf.sfl |
|---|---|
| Message-ID | <[email protected]> |
All, J. G. Van Dyke and Associates (VDA), a Wang Government Services Company, has delivered the Government-Furnished Version 1.6 Certificate Management Library (CML) software and Application Programming Interface (API). The v1.6 CML is available from the Fortezza Developers CML Page (http://www.armadillo.huntsville.al.us/software/certmgmt/index.html). It includes the following enhancements (compared with the v1.56 CML release): 1) Tested with the SNACC, Crypto Token Interface Libraries (CTIL) and LibCert Dynamically Linked Libraries (DLL) delivered with the v1.4 S/MIME Freeware Library (SFL) available from Fortezza Developer's S/MIME Page (http://www.armadillo.huntsville.al.us/software/smime). 2) Tested using MS Windows with the CTIL DLLs for the following crypto libraries: RSA BSAFE v4.2, Crypto++ v3.1, Fortezza Cryptologic Interface (CI) v1.52b and Spyrus SPEX/ v1.52b Release 7b. 3) Tested using Solaris 2.6 with the CTILs as shared objects for the RSA BSAFE v4.2, Fortezza CI v1.52b and Crypto++ v3.1 libraries. 4) Enhanced to process RFC 2459-compliant (i.e. PKIX) Diffie-Hellman certificates. 5) DN Normalization: The rules for comparing DNs were enhanced to be compliant with the 1997 X.500 series of recommendations. 6) CML re-engineered to reduce the number of DLLs by adding the cmdec_c DLL into the cmasn DLL. 7) Implemented short-term solution to allow an application to call CM_RequestCerts to locate a certificate based only on the match criteria specified in the CertMatch_struct structure (i.e. no subject DN is required). For example, CM_RequestCerts can search for a certificate based only on the issuer and serial number fields. 8) Implemented BSAFE (in addition to RSAREF) in the CM_Sigcheck.c module as recommended by Steve Koehler, Secure Computing Corporation. 9) Enhanced Extended Key Usage extension information to provide criticality flag. The v1.6 CML is described in the v1.6 CML API document. It implements the 1997 X.509 certification path processing rules and meets SDN.706 requirements. It (optionally) provides local cache management functions and (optionally) obtains data objects using LDAP v2. It can (optionally) be used in conjunction with the v1.31 Certificate Path Development Library (CPDL) developed by CygnaCom Solutions to provide robust certification path building capabilities such as using cross certificates. The CML has been used to validate X.509 Certificates and Certificate Revocation Lists (CRL) signed using Digital Signature Algorithm (DSA) and RSA. Further enhancements, ports and testing of the CML are still in process. Further releases of the CML will be provided as significant capabilities are added. The following v1.6 CML files are available: CMLv16win.zip -> Windows DLLs CML16so.tar.Z -> Solaris Libraries CML16sr.tar.Z -> Source, include Windows project files The aforementioned files and the v1.6 CML API document (CMv1_6api.doc, CMv1_6api.pdf), test certs (CM155data.zip) and readme.txt files are stored on the Fortezza Developers CML Page. VDA welcomes all feedback regarding the CML software and documents. If bugs are reported, then VDA will investigate each reported bug and, if required, will produce a patch or an updated release of the software to repair the bug. All source code for the CML is being provided at no cost and with no financial limitations regarding its use and distribution. Organizations can use the CML without paying any royalties or licensing fees. The CML was originally developed by the U.S. Government. VDA is enhancing and supporting the CML under contract to the U.S. Government. The U.S. Government is furnishing the CML software at no cost to the vendor subject to the conditions of the CML Public License provided with the CML software. The CML software is not subject to U.S. Government encryption export regulations, so it is freely available to everyone. The v1.6 CML uses the VDA-enhanced SNACC v1.3 ASN.1 Library to encode/decode objects. VDA has successfully tested the v1.6 CML with the SNACC and CTIL DLLs delivered in conjunction with the v1.4 SFL. Source code for the VDA-developed CTILs is available from the Fortezza Developer's S/MIME Page. The actual crypto libraries are not provided with the CML or SFL. They must be independently obtained from the appropriate source. The v1.6 CML can be used in conjunction with the v1.31 CPDL to successfully meet all of the requirements of the Bridge Certification Authority Demonstration effort which includes cross-certified Entrust, Spyrus and Motorola v3 certificate domains. The CMLibv1_6.zip file includes the CPDL source code and public license. http://www.cygnacom.com/cpl provides more information regarding the CPDL. ============================================ John Pawling, Director - Systems Engineering J.G. Van Dyke & Associates, Inc; a Wang Government Services Company [email protected] ============================================