Re: Validating Certs w/out reliable source of Time
Rob Stradling <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hi Max. The most promising solution I've seen to this problem is Google's Roughtime protocol. Adam Langley's blog post: https://www.imperialviolet.org/2016/09/19/roughtime.html Protocol description: https://roughtime.googlesource.com/roughtime/+/HEAD/PROTOCOL.md Open-source implementation: https://roughtime.googlesource.com/roughtime Cloudflare's Roughtime service: https://blog.cloudflare.com/roughtime/ On 04/10/18 15:21, Dr. Pala wrote: > Hi all, > > I am struggling with one issue that we have been seeing more and more > often with the introduction of small IoT devices that connect to clouds > and need to validate the other party's certificate chain. > > In particular, the problem is that without a reliable (or trusted) > source of Time information, devices can not really validate certificates > (i.e., is the certificate even valid... ? is it expired ? is the > revocation info fresh enough ?) and my question for the list is about > best practices in the space. > > Do you know if there are indications / best practices from ITU or from > IETF (or other organizations) on how to deal with this issue ? > > Cheers, > Max > > -- > Best Regards, > Massimiliano Pala, Ph.D. > OpenCA Labs Director > OpenCA Logo -- Rob Stradling Senior Research & Development Scientist Email: [email protected] _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix