Re: [pkix] New draft-ietf-pkix-rfc2560bis-06

"Piyush Jain" <piyush@ditenity.com> Fri, 26 October 2012 16:16 UTC

Return-Path: <piyush@ditenity.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0600D21F863C for <pkix@ietfa.amsl.com>; Fri, 26 Oct 2012 09:16:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.35
X-Spam-Level:
X-Spam-Status: No, score=-3.35 tagged_above=-999 required=5 tests=[AWL=0.249, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id w6-EyJFkOb5T for <pkix@ietfa.amsl.com>; Fri, 26 Oct 2012 09:16:51 -0700 (PDT)
Received: from mail-ie0-f172.google.com (mail-ie0-f172.google.com [209.85.223.172]) by ietfa.amsl.com (Postfix) with ESMTP id 5EE6521F8629 for <pkix@ietf.org>; Fri, 26 Oct 2012 09:16:51 -0700 (PDT)
Received: by mail-ie0-f172.google.com with SMTP id 9so4567272iec.31 for <pkix@ietf.org>; Fri, 26 Oct 2012 09:16:51 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=from:to:cc:references:in-reply-to:subject:date:message-id :mime-version:content-type:content-transfer-encoding:x-mailer :thread-index:content-language:x-gm-message-state; bh=xpaRphAXflZpgUpwPlV/rYVeL26SUO3M3YuBKFf87Y4=; b=bq4orXEIY4LATj0/XBPHDnI+e3kU2JL4RL8hcTfjEAFWN/H78MVeZNSzsc635BB9uc BV2W3PUNKJbSMCo969so0Qw7zCA5O1HxG2Wj/nm6UGM1Qn3rU2w61qh+OUfK8YemBvTp yx0GBtKsCa9Es8vhqxWUYBw6A5HmPlxInhUxtx+7prySFzUYrSr0R3Uz5sdpjXo//Z/5 eR+BgPYs7dx86WaScCFDu3n+wLoqPHwVcSnxkKTEU+6P+f6+d1pEp8eRwSlAgkGTyxJ0 kf2nOvIJKWq9uC+YG9tACmTBJD0CSJ+jpLGHqHW8INFkbTYk23mZJn+EUJP76XmVWaaz 5VlQ==
Received: by 10.50.155.193 with SMTP id vy1mr2590237igb.67.1351268210885; Fri, 26 Oct 2012 09:16:50 -0700 (PDT)
Received: from hp13 (75-25-128-241.lightspeed.sjcpca.sbcglobal.net. [75.25.128.241]) by mx.google.com with ESMTPS id x7sm1519351igk.8.2012.10.26.09.16.48 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 26 Oct 2012 09:16:50 -0700 (PDT)
From: Piyush Jain <piyush@ditenity.com>
To: mrex@sap.com
References: <04d801cdb238$2ac3f350$804bd9f0$@ditenity.com> <20121024224721.EE2201A2F3@ld9781.wdf.sap.corp>
In-Reply-To: <20121024224721.EE2201A2F3@ld9781.wdf.sap.corp>
Date: Fri, 26 Oct 2012 09:16:46 -0700
Message-ID: <009301cdb395$4d4307f0$e7c917d0$@ditenity.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
thread-index: AQHfLv9/VJ87pJZQkWKugh6d3aoOXJeoynxw
Content-Language: en-us
X-Gm-Message-State: ALoCoQnd1hUrX0fXkrj6esnOIkEISe00HhfRS7kmSygdMzEVV0cj0FhJI+4yPcqf5B9B2oLmP6sU
Cc: 'Peter Rybar' <peterryb@gmail.com>, pkix@ietf.org, 'Stefan Santesson' <stefan@aaa-sec.com>
Subject: Re: [pkix] New draft-ietf-pkix-rfc2560bis-06
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Oct 2012 16:16:52 -0000

> 
> The other thing you seem to totally discount is that not every breach of
the
> CAs security amounts to a full and thorough compromise, i.e. that the
> attacker can get hold of an carry away the CA private signature key.
> 
> 

[Piyush] Here is the bulletin published by NIST that pertains to this issue
http://csrc.nist.gov/publications/nistbul/july-2012_itl-bulletin.pdf
NIST recommends revoking the certificate in case of impersonation and RA
compromise and revoking the CA in case of CA system or CA private key
compromise.

Let us know if/why you disagree with these recommendations and the kind of
compromise in which this extension would make sense.