Re: operational protocols

Stef Hoeben <Stefan.Hoeben@esat.kuleuven.ac.be> Mon, 07 April 1997 11:42 UTC

Received: by suntan.tandem.com (8.6.12/suntan5.970212) for ietf-pkix-relay id EAA13682; Mon, 7 Apr 1997 04:42:08 -0700
Received: from barbar.esat.kuleuven.ac.be by suntan.tandem.com (8.6.12/suntan5.970212) for <ietf-pkix@tandem.com> id EAA13668; Mon, 7 Apr 1997 04:41:59 -0700
Received: from dante (dante.esat.kuleuven.ac.be [134.58.66.131]) by barbar (version 8.8.5) with SMTP id NAA26172; Mon, 7 Apr 1997 13:41:16 +0200 (METDST)
Organization: ESAT, K.U.Leuven, Belgium
Date: Mon, 07 Apr 1997 13:41:15 +0200
From: Stef Hoeben <Stefan.Hoeben@esat.kuleuven.ac.be>
X-Sender: hoeben@dante
To: David Boyce <D.Boyce@isode.com>
cc: ietf-pkix@tandem.com
Subject: Re: operational protocols
In-Reply-To: <3208.860410894@isode.com>
Message-ID: <Pine.ULT.3.95.970407132028.241B-100000@dante>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"

On Mon, 7 Apr 1997, David Boyce wrote:
> 
> However, the issue at the heart of the question remains one of the user 
> wanting to establish a legally-binding requirement of service on the 
> Directory, which is quite a different matter.  I don't see that CILs 
> solve this either - if the Directory refuses to provide certs, why 
> should it provide CILs?

If you know a Directory refuses to provide certs, you can do something
about it (complain to the CA, ...). But the problem is to know whether 
a Directory refuses to provide certs or just doesn't have them. I think
the CIL helps you with this:

>From your mail, it looks that , receiving no response from a Directory
after a request can mean:
(1) Your request didn't receive the Directory
(2) The Directory refuses to give you the requested cert
(3) The Directory doesn't have the requested cert
	(are there other possibilities?)
If you have a CIL, (3) can't happen.
By trying again or asking the system admin what's
happing, you can exclude (1) (isn't it?)
So only (2) is left over: if you don't get an answer after
some requests, you know the Directory is tricking you.

Stef