v1.6 Certificate Management Library

"Pawling, John" <[email protected]>
Newsgroups gmane.ietf.sfl
Message-ID <[email protected]>
All,

J. G. Van Dyke and Associates (VDA), a Wang Government Services Company, has
delivered the Government-Furnished Version 1.6 Certificate Management
Library (CML) software and Application Programming Interface (API).  The
v1.6 CML is available from the Fortezza Developers CML Page
(http://www.armadillo.huntsville.al.us/software/certmgmt/index.html).  It
includes the following enhancements (compared with the v1.56 CML release):

1) Tested with the SNACC, Crypto Token Interface Libraries (CTIL) and
LibCert 
Dynamically Linked Libraries (DLL) delivered with the v1.4 S/MIME Freeware 
Library (SFL) available from Fortezza Developer's S/MIME Page 
(http://www.armadillo.huntsville.al.us/software/smime).

2) Tested using MS Windows with the CTIL DLLs for the following crypto 
libraries: RSA BSAFE v4.2, Crypto++ v3.1, Fortezza Cryptologic Interface
(CI) 
v1.52b and Spyrus SPEX/ v1.52b Release 7b. 

3) Tested using Solaris 2.6 with the CTILs as shared objects for the RSA
BSAFE 
v4.2, Fortezza CI v1.52b and Crypto++ v3.1 libraries. 

4) Enhanced to process RFC 2459-compliant (i.e. PKIX) Diffie-Hellman
certificates.  

5) DN Normalization: The rules for comparing DNs were enhanced to be
compliant 
with the 1997 X.500 series of recommendations. 

6) CML re-engineered to reduce the number of DLLs by adding the cmdec_c DLL
into 
the cmasn DLL.

7) Implemented short-term solution to allow an application to call 
CM_RequestCerts to locate a certificate based only on the match criteria 
specified in the CertMatch_struct structure (i.e. no subject DN is
required). 
For example, CM_RequestCerts can search for a certificate based only on the
issuer and serial number fields.

8) Implemented BSAFE (in addition to RSAREF) in the CM_Sigcheck.c module as 
recommended by Steve Koehler, Secure Computing Corporation.

9) Enhanced Extended Key Usage extension information to provide criticality 
flag.

The v1.6 CML is described in the v1.6 CML API document.  It implements the
1997 X.509 certification path processing rules and meets SDN.706
requirements.  It (optionally) provides local cache management functions and
(optionally) obtains data objects using LDAP v2.  It can (optionally) be
used in conjunction with the v1.31 Certificate Path Development Library
(CPDL) developed by CygnaCom Solutions to provide robust certification path
building capabilities such as using cross certificates.  The CML has been
used to validate X.509 Certificates and Certificate Revocation Lists (CRL)
signed using Digital Signature Algorithm (DSA) and RSA.   Further
enhancements, ports and testing of the CML are still in process.  Further
releases of the CML will be provided as significant capabilities are added.


The following v1.6 CML files are available:
CMLv16win.zip -> Windows DLLs 
CML16so.tar.Z -> Solaris Libraries 
CML16sr.tar.Z -> Source, include Windows project files 

The aforementioned files and the v1.6 CML API document
(CMv1_6api.doc, CMv1_6api.pdf), test certs (CM155data.zip) and 
readme.txt files are stored on the Fortezza Developers CML Page.

VDA welcomes all feedback regarding the CML software and documents.  If bugs
are reported, then VDA will investigate each reported bug and, if required,
will produce a patch or an updated release of the software to repair the
bug.

All source code for the CML is being provided at no cost and with no
financial limitations regarding its use and distribution. Organizations can
use the CML without paying any royalties or licensing fees.  The CML was
originally developed by the U.S. Government.  VDA is enhancing and
supporting the CML under contract to the U.S. Government.  The U.S.
Government is furnishing the CML software at no cost to the vendor subject
to the conditions of the CML Public License provided with the CML software.
The CML software is not subject to U.S. Government encryption export
regulations, so it is freely available to everyone.

The v1.6 CML uses the VDA-enhanced SNACC v1.3 ASN.1 Library to encode/decode
objects.  VDA has successfully tested the v1.6 CML with the SNACC and CTIL
DLLs delivered in conjunction with the v1.4 SFL.  Source code for the
VDA-developed CTILs is available from the Fortezza Developer's S/MIME Page.
The actual crypto libraries are not provided with the CML or SFL.  They must
be independently obtained from the appropriate source.  

The v1.6 CML can be used in conjunction with the v1.31 CPDL to successfully
meet all of the requirements of the Bridge Certification Authority
Demonstration effort which includes cross-certified Entrust, Spyrus and
Motorola v3 certificate domains.  The CMLibv1_6.zip file includes the CPDL
source code and public license.  http://www.cygnacom.com/cpl provides more
information regarding the CPDL.

============================================
John Pawling, Director - Systems Engineering
J.G. Van Dyke & Associates, Inc;
a Wang Government Services Company
[email protected]
============================================
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.