1 Nov 2003 11:08
Re: Web-PKI Keygen/Certreq Questions
Anders Rundgren <anders.rundgren <at> telia.com>
2003-11-01 10:08:42 GMT
2003-11-01 10:08:42 GMT
Pierre, We apparently agree on the state of affaires. Regarding your particular concerns, I am slightly less in agreement as I see on-line certification being a provider-defined activity. To in a PKCS #10 client-created packet "ask" for certain DN attributes does not apply to such scenarios. It is rather "all-on-the-server". At least the systems that are rolled out in Europe are definitely of that type and I think this make sense as well. PKIX standards (as well as current browser implementations), where designed for a "collaborative" environment where the user often is supposed to know about things like key length etc. But PKIs for on-line banking and e-Governments (C2G) are targeted at user groups who essentially know nothing about PKI. The (mostly Java-written) systems I have seen in these areas are all designed to hide PKI as much as it is technically possible. These systems, AFAIK, all take a "complete grip" on the whole process from on-line certification to on-line (web) signatures. I don't know exactly where that leaves current PKIX standards or what to do next though. To get the browser vendors (which are at least five taking the mobile dittos also in consideration), to cooperate is a major task. It might actually be easier to define "the whole thing" (on-line Web-PKI) from scratch using XML and perform this work in W3C(Continue reading)
.
Peter.
RSS Feed