Re: Requesting information on Time stamp authority certificate expiry.

Anoop Gulati <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <CAEZbciuMv5X-nC8TwYAx2EAhOhCiW4D1o+2YqK-N420UCJDT0g@mail.gmail.com>
Many thanks for the responses and further explanation on the workings of
the TSA.

This poses a logistical challenge of redistributing a new signed copy of
code.
Also, apart from monitoring signing key expiration, we now also got to
monitor TSA key expiration.

I agree with your description of the TSA service, “I successfully validated
the signature on this object at time X", but apps & platforms not
acknowledging this fact post TSA key expiry is whats causing the impact.
I also agree with your point: "If there is a chain one may be able to infer
things, but changes in algorithms can kill you.", but this can be managed
as all previous alg. changes have been dealt with on an OS level.
e.g.:
https://social.technet.microsoft.com/wiki/contents/articles/32288.windows-enforcement-of-sha1-certificates.aspx
.




On Fri, Jan 5, 2018 at 10:00 PM, Jim Schaad <[email protected]> wrote:

>
>
> > -----Original Message-----
> > From: Peter Gutmann [mailto:[email protected]]
> > Sent: Friday, January 5, 2018 6:27 PM
> > To: Jim Schaad <[email protected]>; 'Anoop Gulati'
> > <[email protected]>; [email protected]
> > Subject: Re: [pkix] Requesting information on Time stamp authority
> > certificate expiry.
> >
> > Jim Schaad <[email protected]> writes:
> >
> > >The correct rule ought to be, when the TSA certificate expires the
> > >signature expires and it no longer tells you anything more.
> >
> > Just because the cert has expired doesn't mean the signature
> automatically
> > invalidates itself.  The TSA countersig still tells you that the signed
> item was
> > OK at time X, if you securely store a copy of it after the expiry time
> (or
> > countersign it yourself, or whatever) you can refer back to your
> known-good
> > copy to check that it's still OK.
>
> I was referring to the TSA signature not the original signature.  On a new
> copy you cannot assume anything.  I agree that if you securely store the
> item while it was originally good then you can still make some assumptions
> about it still being the same as it originally was.
>
>
> >
> > It's really an ecumenical matt^H^H^Hpolicy issue as to how you manage
> this.
> >
> > Peter.
>
>

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.