Re: [pkix] New draft-ietf-pkix-rfc2560bis-06

"Piyush Jain" <piyush@ditenity.com> Wed, 24 October 2012 22:37 UTC

Return-Path: <piyush@ditenity.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA86B1F0C4C for <pkix@ietfa.amsl.com>; Wed, 24 Oct 2012 15:37:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.293
X-Spam-Level:
X-Spam-Status: No, score=-3.293 tagged_above=-999 required=5 tests=[AWL=0.306, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WLj963uiqa92 for <pkix@ietfa.amsl.com>; Wed, 24 Oct 2012 15:37:40 -0700 (PDT)
Received: from mail-ia0-f172.google.com (mail-ia0-f172.google.com [209.85.210.172]) by ietfa.amsl.com (Postfix) with ESMTP id 4A1761F0C49 for <pkix@ietf.org>; Wed, 24 Oct 2012 15:37:40 -0700 (PDT)
Received: by mail-ia0-f172.google.com with SMTP id o25so925983iad.31 for <pkix@ietf.org>; Wed, 24 Oct 2012 15:37:39 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=from:to:cc:references:in-reply-to:subject:date:message-id :mime-version:content-type:content-transfer-encoding:x-mailer :thread-index:content-language:x-gm-message-state; bh=auRHuGmoj+70J6ZfXXSMTacHZ2SlJphXr40/h8Q6oWI=; b=VxhQxMZkRpCEhmLZ9sHtZKOfrI/zt56mP/8jHVP6j3E0uxJik8wjyK5TnRw/qeMdzD zrj2TWeLcAfq2S9kPTcSdooS8MUCgIA9h6DqrgXgV52UMMJAFQimfvV44KQoYtp/qXhC rmC5ymVGNEtQrywJhYwS48uPy+BpIxAYd60AAcULXfruhinjq9gUqm88nGvTCYpthqr2 44INZsfx86kwhjZmRfjBMBrDVxAGpbN5EGr//80EPdJcXskFXEW4I5p66D9vsVa92GNb HgV33GWJjtAAgVnOying42mmdbQ0cC+mrrnONJuTJQUTZXPYcnplsgIo4d3nUI6oOdrk X6Tw==
Received: by 10.50.46.226 with SMTP id y2mr4038122igm.62.1351118259681; Wed, 24 Oct 2012 15:37:39 -0700 (PDT)
Received: from hp13 (75-25-128-241.lightspeed.sjcpca.sbcglobal.net. [75.25.128.241]) by mx.google.com with ESMTPS id s3sm3097848igb.14.2012.10.24.15.37.37 (version=TLSv1/SSLv3 cipher=OTHER); Wed, 24 Oct 2012 15:37:38 -0700 (PDT)
From: Piyush Jain <piyush@ditenity.com>
To: mrex@sap.com
References: <20121024181016.503F21A2F3@ld9781.wdf.sap.corp> <20121024202252.E840F1A2F3@ld9781.wdf.sap.corp>
In-Reply-To: <20121024202252.E840F1A2F3@ld9781.wdf.sap.corp>
Date: Wed, 24 Oct 2012 15:37:25 -0700
Message-ID: <04d801cdb238$2ac3f350$804bd9f0$@ditenity.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQFjmKQCMxFNIb8xC0cxdK32fyOSLpidPfvQ
Content-Language: en-us
X-Gm-Message-State: ALoCoQmXVkaYIjWo1qyTeDn/Nok/6xuaKXu2LP5oxwex5MEvxxOMBMa0Cx3VDDNxSeMroN3yN7pW
Cc: 'Peter Rybar' <peterryb@gmail.com>, pkix@ietf.org, 'Stefan Santesson' <stefan@aaa-sec.com>
Subject: Re: [pkix] New draft-ietf-pkix-rfc2560bis-06
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Oct 2012 22:37:40 -0000

 
> The "cert hash" in the OCSP response option protects against
hash-collisions
> and fraudulently issued without record of certs that re-use the serial of
> regular valid certs to appear innocent from not being detectable.
> 
> So that cert hash should probably use at least SHA-256.  Being a new
protocol
> feature, that ought to be easy (we skipped SHA-1 in DANE as well).

[Piyush]  I think you mean appears to protect. 
I hope people really don't start believing that this extension protects them
from a CA compromise scenario.


> 
> 
> -Martin
> _______________________________________________
> pkix mailing list
> pkix@ietf.org
> https://www.ietf.org/mailman/listinfo/pkix