RE: Online Certificate Revocation Protocol
"JANES, Mark" <Mark.JANES@sema.co.uk> Fri, 08 June 2001 15:17 UTC
Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id LAA14174 for <pkix-archive@odin.ietf.org>; Fri, 8 Jun 2001 11:17:00 -0400 (EDT)
Received: (from majordomo@localhost) by above.proper.com (8.9.3/8.9.3) id HAA29900 for ietf-pkix-bks; Fri, 8 Jun 2001 07:34:08 -0700 (PDT)
Received: from mailrelay1.sema.co.uk ([194.216.60.137]) by above.proper.com (8.9.3/8.9.3) with ESMTP id HAA29892 for <ietf-pkix@imc.org>; Fri, 8 Jun 2001 07:34:01 -0700 (PDT)
Received: from lonns01.sema.co.uk ([157.203.40.61]) by mailrelay1.sema.co.uk (8.9.3/8.9.3) with ESMTP id OAA21574 for <ietf-pkix@imc.org>; Fri, 8 Jun 2001 14:28:18 +0100
Received: from lones3.sema.co.uk (unverified) by lonns01.sema.co.uk (Content Technologies SMTPRS 4.2.1) with ESMTP id <T54050eb3e49dcb283d075@lonns01.sema.co.uk> for <ietf-pkix@imc.org>; Fri, 8 Jun 2001 15:28:22 +0100
Received: by lones3.sema.co.uk with Internet Mail Service (5.5.2653.19) id <MJCYD79G>; Fri, 8 Jun 2001 15:31:14 +0100
Message-ID: <95E3FBC144C1D411A1AB0090271F735D012C139E@wiles2.sema.co.uk>
From: "JANES, Mark" <Mark.JANES@sema.co.uk>
To: ietf-pkix@imc.org
Subject: RE: Online Certificate Revocation Protocol
Date: Fri, 08 Jun 2001 15:31:03 +0100
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: text/plain; charset="iso-8859-1"
Sender: owner-ietf-pkix@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
List-ID: <ietf-pkix.imc.org>
Does anyone know what implementations of CMP exist? Thanks, Mark Janes Principal Technical Architect e-Government Services SchlumbergerSema UK Region *Office: (+44) (0) 1625 88 4698 NNH Wilmslow *Fax: (+44) (0) 1625 530 911 NNH Wilmslow *Mobile: (+44) (0) 7733 310 313 * Email: Mark.Janes@sema.co.uk * Postal: Ground Floor East, Norcliffe House, Station Road, Wilmslow, SK9 1BB -----Original Message----- From: Nada Kapidzic Cicovic [mailto:nada@entegrity.com] Sent: 08 June 2001 12:21 To: madwolf@openca.org; ietf-pkix@imc.org Subject: Re: Online Certificate Revocation Protocol At 11:01 AM 6/8/01 +0200, Massimiliano Pala wrote: >Carlin Covey wrote: > > > But none of these allow a certificate to be revoked. I gather that > > you are interested in a protocol for requesting revocation of certificates. > > Check out CMP, available at > > http://www.ietf.org/internet-drafts/draft-ietf-pkix-rfc2510bis-04.txt > >This could be the case, anyway I was thinking of something more "robust" >and a little bit complex -- as request/response contents -- to prevent >unauthorized revoking requesting to prevent as much as possible DoS but >allowing for a simple revocation method. This could help environments where >legal issues are also covered -- govenment PKIs, Municipalities PKIs, >etc... This is exactly what CMP specifies. Many vendors already have support for CMP EE initiated certificate revocation. The interoperability of different implementations of CMP certificate revocation (among other things) has been conducted during PKI Forum and ICSA CMP interop testing quite successfully. Nada >The model I've been thinking of is mostly based on a structure very similar >to the model proposed in OCSP. The choosen transport mechanism could be >HTTP -- this could help browsers in adding the functionality and CSP to >implement the service. > >-- > >C'you, > > Massimiliano Pala > >--o------------------------------------------------------------------------ - >Massimiliano Pala [OpenCA Project Manager] madwolf@openca.org > madwolf@hackmasters.net >http://www.openca.org Tel.: +39 (0)59 270 094 >http://openca.sourceforge.net Mobile: +39 (0)347 7222 365 ______________________________________________________________ Nada Kapidzic Cicovic, Ph.D. Technical Director, Entegrity Solutions office: + 46 8 477 77 37, cell: + 46 70 495 09 03, fax: + 46 8 477 77 31 ___________________________________________________________________________ This email is confidential and intended solely for the use of the individual to whom it is addressed. Any views or opinions presented are solely those of the author and do not necessarily represent those of Sema. If you are not the intended recipient, be advised that you have received this email in error and that any use, dissemination, forwarding, printing, or copying of this email is strictly prohibited. If you have received this email in error please notify the Sema UK Helpdesk by telephone on +44 (0) 121 627 5600. ___________________________________________________________________________
- RE: Online Certificate Revocation Protocol JANES, Mark
- Online Certificate Revocation Protocol Massimiliano Pala
- Online Certificate Revocation Protocol Massimiliano Pala
- Re: Online Certificate Revocation Protocol Hansen Wang
- RE: Online Certificate Revocation Protocol Carlin Covey
- RE: Online Certificate Revocation Protocol Peter Williams
- RE: Online Certificate Revocation Protocol Frank Balluffi
- Re: Online Certificate Revocation Protocol Massimiliano Pala
- Re: Online Certificate Revocation Protocol Massimiliano Pala
- Re: Online Certificate Revocation Protocol Nada Kapidzic Cicovic
- Re: Online Certificate Revocation Protocol Massimiliano Pala
- Re: Online Certificate Revocation Protocol Peter Gutmann
- RE: Online Certificate Revocation Protocol Peter Gutmann
- Re: Online Certificate Revocation Protocol Massimiliano Pala
- Re: Online Certificate Revocation Protocol Housley, Russ
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- Re: Online Certificate Revocation Protocol Tony Bartoletti
- Re: Online Certificate Revocation Protocol Tony Bartoletti
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- Re: Online Certificate Revocation Protocol Andrew W. Gray
- Re: Online Certificate Revocation Protocol Paul Hoffman / IMC
- Re: Online Certificate Revocation Protocol Hansen Wang
- Re: Online Certificate Revocation Protocol Tony Bartoletti
- Re: Online Certificate Revocation Protocol Tony Bartoletti
- Re: Online Certificate Revocation Protocol Marc Branchaud
- RE: Online Certificate Revocation Protocol Paul Gogarty
- Re: Online Certificate Revocation Protocol jim
- Re: Online Certificate Revocation Protocol Hansen Wang
- Online Certificate Revocation Protocol Mr Jonathan W Jenkyn
- Re: Online Certificate Revocation Protocol Hansen Wang
- Online Certificate Revocation Protocol Massimiliano Pala
- Re: Online Certificate Revocation Protocol Massimiliano Pala
- Online Certificate Revocation Protocol Massimiliano Pala
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- Re: Online Certificate Revocation Protocol Paul Hoffman / IMC
- Re: Online Certificate Revocation Protocol jim
- Re: Online Certificate Revocation Protocol Peter Gutmann
- Re: Online Certificate Revocation Protocol Peter Gutmann
- Re: Online Certificate Revocation Protocol Peter Gutmann
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- Re: Online Certificate Revocation Protocol Massimiliano Pala
- Re: Online Certificate Revocation Protocol Bob Jueneman
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Carlin Covey
- Re: Online Certificate Revocation Protocol Marc Branchaud
- RE: Online Certificate Revocation Protocol Tony Bartoletti
- Re: Online Certificate Revocation Protocol Tony Bartoletti
- Re: Online Certificate Revocation Protocol Marc Branchaud
- Re: Online Certificate Revocation Protocol Marc Branchaud
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- Re: Online Certificate Revocation Protocol Massimiliano Pala
- RE: Online Certificate Revocation Protocol Lynn.Wheeler
- Re: Online Certificate Revocation Protocol Marc Branchaud
- RE: Online Certificate Revocation Protocol Carlin Covey
- RE: Online Certificate Revocation Protocol Lynn.Wheeler
- RE: Online Certificate Revocation Protocol Paul Gogarty
- RE: Online Certificate Revocation Protocol Scherling, Mark
- RE: Online Certificate Revocation Protocol Carlin Covey
- RE: Online Certificate Revocation Protocol Scherling, Mark
- RE: Online Certificate Revocation Protocol Bob Jueneman
- RE: Online Certificate Revocation Protocol Scherling, Mark
- Re: Online Certificate Revocation Protocol Terry Hayes
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Scherling, Mark
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Scherling, Mark
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Carlin Covey
- Re: Online Certificate Revocation Protocol Peter Gutmann
- RE: Online Certificate Revocation Protocol Lynn.Wheeler
- Re: Online Certificate Revocation Protocol Massimiliano Pala
- Re: Online Certificate Revocation Protocol jim
- Re: Online Certificate Revocation Protocol jim
- Re: Online Certificate Revocation Protocol Lynn.Wheeler
- Re: Online Certificate Revocation Protocol Tony Bartoletti
- Re: Online Certificate Revocation Protocol Tony Bartoletti
- RE: Online Certificate Revocation Protocol Scherling, Mark
- RE: Online Certificate Revocation Protocol Hal Lockhart
- Re: Online Certificate Revocation Protocol Peter Gutmann
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- Re: Online Certificate Revocation Protocol jim
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Liaquat Khan
- RE: Online Certificate Revocation Protocol Scherling, Mark
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- Re: Online Certificate Revocation Protocol Tony Bartoletti
- RE: Online Certificate Revocation Protocol Scherling, Mark
- RE: Online Certificate Revocation Protocol Santosh Chokhani
- RE: Online Certificate Revocation Protocol Tony Bartoletti
- Re: Online Certificate Revocation Protocol jim
- RE: Online Certificate Revocation Protocol Luis Azevedo
- Re: Online Certificate Revocation Protocol Denis Pinkas
- Re: Online Certificate Revocation Protocol Peter Gutmann
- RE: Online Certificate Revocation Protocol Liaquat Khan
- Re: Online Certificate Revocation Protocol Denis Pinkas
- Re: Online Certificate Revocation Protocol Denis Pinkas
- Re: Online Certificate Revocation Protocol Nick Pope