Online Certificate Revocation Protocol

Massimiliano Pala <madwolf@openca.org> Thu, 07 June 2001 23:26 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id TAA16081 for <pkix-archive@odin.ietf.org>; Thu, 7 Jun 2001 19:26:05 -0400 (EDT)
Received: by above.proper.com (8.9.3/8.9.3) id PAA17014 for ietf-pkix-bks; Thu, 7 Jun 2001 15:50:27 -0700 (PDT)
Received: from mail.hackmasters.net (IDENT:postfix@[217.133.253.143]) by above.proper.com (8.9.3/8.9.3) with ESMTP id PAA17010 for <ietf-pkix@imc.org>; Thu, 7 Jun 2001 15:50:20 -0700 (PDT)
Received: from openca.org (galadriel.mpcnet.org [10.5.122.180]) by mail.hackmasters.net (Postfix) with ESMTP id A59E13CEE for <ietf-pkix@imc.org>; Fri, 8 Jun 2001 01:55:54 +0200 (CEST)
Message-ID: <3B200613.7D2EB03B@openca.org>
Date: Fri, 08 Jun 2001 00:54:11 +0200
From: Massimiliano Pala <madwolf@openca.org>
Reply-To: madwolf@openca.org
Organization: OpenCA
X-Mailer: Mozilla 4.77 [en] (X11; U; Linux 2.2.18 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: ietf-pkix@imc.org
Subject: Online Certificate Revocation Protocol
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-pkix@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
List-ID: <ietf-pkix.imc.org>
Content-Transfer-Encoding: 7bit

Hi all,

I am in search of some help and suggestions about certificate revocation. The
problem is that, as far as I know, no rfc covers a possible online revocation
protocol to be used to revoke a certificate.

The model I am thinking of is request-response oriented and, depending on
the policy adopted by the corresponding CA, permits a user/router/etc... to
ask for revocation of a certificate. This can help environments where
certificates from different vendors are used and we want to be able to ask
for revocation without having to follow different procedures for different
CSP -- additional steps could/shall, depending on the policy adopted,
be taken to accomplish the revocation process.

Has my problem a solution yet ??? Or can I work on a proposal to be
submitted for comments and reviews ???

Looking forwards for comments.

-- 

Best Regards,

	Massimiliano Pala

--o-------------------------------------------------------------------------
Massimiliano Pala [OpenCA Project Manager]                madwolf@openca.org
                                                     madwolf@hackmasters.net
http://www.openca.org                            Tel.:   +39 (0)59  270  094
http://openca.sourceforge.net                    Mobile: +39 (0)347 7222 365