Re: Online Certificate Revocation Protocol

Paul Hoffman / IMC <phoffman@imc.org> Sat, 09 June 2001 21:01 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id RAA18747 for <pkix-archive@odin.ietf.org>; Sat, 9 Jun 2001 17:01:43 -0400 (EDT)
Received: by above.proper.com (8.11.3/8.11.3) id f59Jrpg02149 for ietf-pkix-bks; Sat, 9 Jun 2001 12:53:51 -0700 (PDT)
Received: from [165.227.249.18] (ip18.proper.com [165.227.249.18]) by above.proper.com (8.11.3/8.11.3) with ESMTP id f59JroJ02136 for <ietf-pkix@imc.org>; Sat, 9 Jun 2001 12:53:50 -0700 (PDT)
Mime-Version: 1.0
X-Sender: phoffman@mail.imc.org
Message-Id: <p05100322b7482ef536e1@[165.227.249.18]>
Date: Sat, 09 Jun 2001 12:52:22 -0700
To: ietf-pkix@imc.org
From: Paul Hoffman / IMC <phoffman@imc.org>
Subject: Re: Online Certificate Revocation Protocol
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: owner-ietf-pkix@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
List-ID: <ietf-pkix.imc.org>

At 5:57 PM -0700 6/8/01, Hansen Wang wrote:
>But out-of-band could also mean going to the CA's web page and filling
>out a form such as typing in the some passwords/passphrase, presenting
>some electronic credentials or mother's maiden name (bad example) to
>request for the revocation. This would not involve staffing and would be
>nearly as quick as sending the revocation message through "in-band"
>means.

Exactly. But it is up to each CA, and we can't determine what they 
should do here.

--Paul Hoffman, Director
--Internet Mail Consortium