Re: Online Certificate Revocation Protocol

Hansen Wang <hansen.wang@home.com> Fri, 08 June 2001 01:09 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id VAA16943 for <pkix-archive@odin.ietf.org>; Thu, 7 Jun 2001 21:09:14 -0400 (EDT)
Received: by above.proper.com (8.9.3/8.9.3) id RAA25441 for ietf-pkix-bks; Thu, 7 Jun 2001 17:40:54 -0700 (PDT)
Received: from mail2.rdc2.bc.home.com (mail2.rdc2.bc.home.com [24.2.10.85]) by above.proper.com (8.9.3/8.9.3) with ESMTP id RAA25428 for <ietf-pkix@imc.org>; Thu, 7 Jun 2001 17:40:46 -0700 (PDT)
Received: from home.com ([24.76.94.62]) by mail2.rdc2.bc.home.com (InterMail vM.4.01.03.20 201-229-121-120-20010223) with ESMTP id <20010608004037.PGEL862.mail2.rdc2.bc.home.com@home.com>; Thu, 7 Jun 2001 17:40:37 -0700
Message-ID: <3B201DED.6D86559E@home.com>
Date: Thu, 07 Jun 2001 17:35:57 -0700
From: Hansen Wang <hansen.wang@home.com>
Reply-To: hansenw@ece.ubc.ca
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.5-15 i586)
X-Accept-Language: en
MIME-Version: 1.0
To: madwolf@openca.org
CC: ietf-pkix@imc.org
Subject: Re: Online Certificate Revocation Protocol
References: <3B200613.7D2EB03B@openca.org>
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-pkix@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
List-ID: <ietf-pkix.imc.org>
Content-Transfer-Encoding: 7bit

Massimiliano Pala wrote:
> 
> Hi all,
> 
> I am in search of some help and suggestions about certificate revocation. The
> problem is that, as far as I know, no rfc covers a possible online revocation
> protocol to be used to revoke a certificate.

Isn't that what OCSP supposed to do? RFC 2560

2560 X.509 Internet Public Key Infrastructure Online Certificate
Status Protocol - OCSP. M. Myers, R. Ankney, A. Malpani, S. Galperin,
C. Adams. June 1999.

Also Certificate Revocation Status is also a per request - per response
system.


> 
> The model I am thinking of is request-response oriented and, depending on
> the policy adopted by the corresponding CA, permits a user/router/etc... to
> ask for revocation of a certificate. This can help environments where
> certificates from different vendors are used and we want to be able to ask
> for revocation without having to follow different procedures for different
> CSP -- additional steps could/shall, depending on the policy adopted,
> be taken to accomplish the revocation process.
> 
> Has my problem a solution yet ??? Or can I work on a proposal to be
> submitted for comments and reviews ???

-
Hansen Wang
<http://members.home.net/hansen.wang/