Re: [Asrg] Consent Proposal

Yakov Shafranovich <research@solidmatrix.com> Wed, 02 July 2003 20:09 UTC

Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA10581 for <asrg-archive@odin.ietf.org>; Wed, 2 Jul 2003 16:09:10 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19XnuG-0000WC-9n for asrg-archive@odin.ietf.org; Wed, 02 Jul 2003 16:08:44 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id h62K8iOA001986 for asrg-archive@odin.ietf.org; Wed, 2 Jul 2003 16:08:44 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19XnuG-0000Vx-5a for asrg-web-archive@optimus.ietf.org; Wed, 02 Jul 2003 16:08:44 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA10569; Wed, 2 Jul 2003 16:08:39 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19XnuC-0006m2-00; Wed, 02 Jul 2003 16:08:40 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19XnuC-0006lz-00; Wed, 02 Jul 2003 16:08:40 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19XntZ-0000NS-IN; Wed, 02 Jul 2003 16:08:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19XntK-0000Jh-Vm for asrg@optimus.ietf.org; Wed, 02 Jul 2003 16:07:47 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA10547 for <asrg@ietf.org>; Wed, 2 Jul 2003 16:07:42 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19XntH-0006lH-00 for asrg@ietf.org; Wed, 02 Jul 2003 16:07:43 -0400
Received: from 000-257-002.area7.spcsdns.net ([68.27.243.209] helo=68.27.243.209) by ietf-mx with smtp (Exim 4.12) id 19XntC-0006lA-00 for asrg@ietf.org; Wed, 02 Jul 2003 16:07:42 -0400
Message-Id: <5.2.0.9.2.20030702155950.00bd5138@std5.imagineis.com>
X-Sender: research@solidmatrix.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
To: Markus Stumpf <maex-lists-spam-ietf-asrg@Space.Net>, "Asrg@Ietf. Org" <asrg@ietf.org>
From: Yakov Shafranovich <research@solidmatrix.com>
Subject: Re: [Asrg] Consent Proposal
In-Reply-To: <20030702184054.B82235@Space.Net>
References: <HKEFKPNPJLANNFPFMDKJIELDIIAA.danny@apache.org> <20030702015753.F74353@Space.Net> <HKEFKPNPJLANNFPFMDKJIELDIIAA.danny@apache.org>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-MimeHeaders-Plugin-Info: v2.03.00
X-GCMulti: 1
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Wed, 02 Jul 2003 16:07:15 -0400

At 06:40 PM 7/2/2003 +0200, Markus Stumpf wrote:

>On Wed, Jul 02, 2003 at 09:38:22AM +0100, Danny Angus wrote:
> > What does work are the mechanisms which exist for propogating and
> > revoking trust, that you don't trust anyone is a completely different 
> issue.
>
>Ok, what are the "mechanisms which exist for propogating and revoking trust"?
>Newspapers? I don't know of any technically oriented ones. Or more
>specifically: What do I have to do so that my browser can check whether
>a SSL cert for a website has been revoked?

See RFC 2459, sections 5 and 3.3 and RFC 2560

In Internet Explorer options screen (IE6), under "Advanced", "Security", 
the first  two options listed are:

"Check for publisher's certificate revocation"
"Check for server certificate revocation"

Netscape 7 and Mozilla include an option in under "Security", "Validation" 
to use the Online Certificate Status Protocol (OCSP) to verify 
certificates. This protocol is defined in RFC 2560.

Funny enough Opera 7 has none of these options but IE does. Weird.

Yakov 


_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg