Re: Validating Certs w/out reliable source of Time
"Dr. Pala" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Organization | OpenCA Labs |
| Message-ID | <[email protected]> |
Hi Tom, On 10/8/18 9:00 AM, Tom Ritter wrote: > On Mon, 8 Oct 2018 at 14:13, Dr. Pala <[email protected] > <mailto:[email protected]>> wrote: > > Hi Panos, all, > > [...] > > > If you use OCSP in a challenge-response mode with nonces - you could > get this within established TLS/PKIX standards. Although OCSP > challenge/response (as opposed to stapling) is falling out favor; and > OCSP nonces stopped being used over a decade ago. But I don't think > the code is removed from tools; just uncommonly used. > > Caveats being; of course, the uptime of your time/OCSP server; > difficulty of rotating that server's certificate, what to do when you > don't get a response.... For our specific case, we considered using the OCSP responses since our servers do support NONCEs and do not have ridiculously long validity/caching period (as it seems current practices from many CAs), however that might not be a good path for a generic solution (beacuse of current practices). I am also considering other protocols (e.g., SCVP) and cross-protocols options (e.g., DNS entries/extensions, etc.) - however the constraints on network access might make these approaches also difficult... Thanks again, Cheers, -- Best Regards, Massimiliano Pala, Ph.D. OpenCA Labs Director OpenCA Logo _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix
smime.p7s
(application/pkcs7-signature, 3.9 KB) - not displayed