Re: Validating Certs w/out reliable source of Time

"Panos Kampanakis (pkampana)" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Hi Max,


This is an issue that is dealt with in onboarding too. https://tools.ietf.org/html/draft-ietf-anima-bootstrapping-keyinfra-16#section-2.6 has some text around it. It states “It is reasonable that the
      notBefore date be after the pledge's current working reasonable
      date.  It is however, suspicious for the notAfter date to be
      before the pledge's current reasonable date.  No action is
      recommended, other than an internal audit entry for this.”
IMO, if someone trusted a server cert chain because he didn’t have proper time at the time, he should generate an audit log that can be used to go back to validate when more accurate time available.

There was also a discussion in LAMPS about trusting expired certs in the initial enrollment https://mailarchive.ietf.org/arch/browse/spasm/?q=%22Permissibility+of+expired+cert+renewal%22 . Caching revocation info for the chain is important in these cases.

Rgs,
Panos

From: pkix <[email protected]> On Behalf Of Dr. Pala
Sent: Thursday, October 04, 2018 10:22 AM
To: PKIX <[email protected]>
Subject: [pkix] Validating Certs w/out reliable source of Time


Hi all,

I am struggling with one issue that we have been seeing more and more often with the introduction of small IoT devices that connect to clouds and need to validate the other party's certificate chain.

In particular, the problem is that without a reliable (or trusted) source of Time information, devices can not really validate certificates (i.e., is the certificate even valid... ? is it expired ? is the revocation info fresh enough ?) and my question for the list is about best practices in the space.

Do you know if there are indications / best practices from ITU or from IETF (or other organizations) on how to deal with this issue ?

Cheers,
Max
--
Best Regards,
Massimiliano Pala, Ph.D.
OpenCA Labs Director
[OpenCA Logo]

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
image001.png (image/png, 3.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.