1 Feb 2008 12:12
Re: WG Review: Recharter of Public-Key Infrastructure (X.509) (pkix)
Denis Pinkas <denis.pinkas <at> bull.net>
2008-02-01 11:12:37 GMT
2008-02-01 11:12:37 GMT
A few comments. (...) >PKIX will pursue new work items in the PKI arena if working group >members express sufficient interest, and if approved by the cognizant >Security Area director. For example, certificate validation under X. >509 and PKIX standards calls for a relying party to use a trust >anchor as the start of a certificate path. This is not fully correct. Proposed change: "For example, certificate validation under X. 509 and PKIX standards calls for a relying party to use *one or more* trust anchors and optional *additional conditions* as the start of a certificate path". > Neither X.509 nor extant >PKIX standards define protocols for the management of trust anchors. This is untrue. RFC 4210 "PKI Certificate Management Protocols" (CMP) defines data structures that allow to change a single trust anchor. The posting of these data structures which are certificates allow to change gracefully one trust anchor. These certificates may be placed in a directory and can be retrieved using any kind of protocol able to obtain ordinary certificates. Page 9 :(Continue reading)
RSS Feed