Re: PKI Resources Query Protocol
2005-07-01 07:29:22 GMT
Massimiliano, >I am working on the definition of a new protocol aimed to solve the problem >tied to the lack of informations about repositories and services offered >by a CSP. OK. Does that also include warranties? >One of the problems we are facing now is how to connect different >closed existing PKIs. What do you mean with "connect"? I thought that NIST and other US government bodies already consider this solved by using bridge CAs. (personally I believe bridges will rarely reach outside of the public sector border as neither the implicit trust model, nor the bridge CA business model are particularly suited for the commercial world) >For this purpose I think that the availability of URI about offered services >(e.g. OCSP, SCVP, etc... ) or available data (e.g. certificate and CRLs >repositories) would help in PKI interoperability. How do you find the URI? In a certificate extension or OOB? >Therefore I am trying to work on this subject by defining a newprotocol. >Reasons to adopt such a protocol are: >- extensions are too static, if new services or repositories are added > (or dismissed) by the CSP, there is no sign of the changes into the > already issued certificates >- no need to define new type of extensions for new services and/or(Continue reading)
RSS Feed