Re: Optimizing OCSP - Time for some spec work ?

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
David A. Cooper <[email protected]> writes:

>I also don't see how this "I've checked the entire chain from the cert you
>requested all the way up to the root.  You're welcome" extension would work.

See my previous message, it's not meant to be perfect, just an improvement on
current usage.  In particular:

>Consider a scenario in which a CA's private key had been compromised, and its
>certificate had been revoked.

In that case the browser vendors [0 again, from the previous message] push out
an emergency update because they don't trust revocation checking to get the
job done.

So it really depends on the usage scenario.  If you can make it better than
the current mess, that's at least some progress.

Peter.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.