Re: Validating Certs w/out reliable source of Time

"Dr. Pala" <[email protected]>
Newsgroups gmane.ietf.x509
Organization OpenCA Labs
Message-ID <[email protected]>
Hi Tom,


On 10/8/18 9:00 AM, Tom Ritter wrote:
> On Mon, 8 Oct 2018 at 14:13, Dr. Pala <[email protected] 
> <mailto:[email protected]>> wrote:
>
>     Hi Panos, all,
>
>     [...]
>
>
> If you use OCSP in a challenge-response mode with nonces - you could 
> get this within established TLS/PKIX standards. Although OCSP 
> challenge/response (as opposed to stapling) is falling out favor; and 
> OCSP nonces stopped being used over a decade ago. But I don't think 
> the code is removed from tools; just uncommonly used.
>
> Caveats being; of course, the uptime of your time/OCSP server; 
> difficulty of rotating that server's certificate, what to do when you 
> don't get a response....

For our specific case, we considered using the OCSP responses since our 
servers do support NONCEs and do not have ridiculously long 
validity/caching period (as it seems current practices from many CAs), 
however that might not be a good path for a generic solution (beacuse of 
current practices). I am also considering other protocols (e.g., SCVP) 
and cross-protocols options (e.g., DNS entries/extensions, etc.) - 
however the constraints on network access might make these approaches 
also difficult...

Thanks again,

Cheers,

-- 
Best Regards,
Massimiliano Pala, Ph.D.
OpenCA Labs Director
OpenCA Logo

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
smime.p7s (application/pkcs7-signature, 3.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.