RE: request for WG to adopt draft-chadwick-webdav-00.txt as a work item

Stefan Santesson <stefans@microsoft.com> Tue, 11 September 2007 13:46 UTC

Return-path: <owner-ietf-pkix@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1IV64C-0002v4-65 for pkix-archive@lists.ietf.org; Tue, 11 Sep 2007 09:46:12 -0400
Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IV64A-00038x-Na for pkix-archive@lists.ietf.org; Tue, 11 Sep 2007 09:46:12 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l8BCpcDK082484 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 11 Sep 2007 05:51:38 -0700 (MST) (envelope-from owner-ietf-pkix@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l8BCpcwH082483; Tue, 11 Sep 2007 05:51:38 -0700 (MST) (envelope-from owner-ietf-pkix@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-pkix@mail.imc.org using -f
Received: from smtp-dub.microsoft.com (smtp-dub.microsoft.com [213.199.138.191]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l8BCpXPA082473 (version=TLSv1/SSLv3 cipher=RC4-MD5 bits=128 verify=NO) for <ietf-pkix@imc.org>; Tue, 11 Sep 2007 05:51:37 -0700 (MST) (envelope-from stefans@microsoft.com)
Received: from dub-exhub-c302.europe.corp.microsoft.com (65.53.213.92) by DUB-EXGWY-E801.partners.extranet.microsoft.com (10.251.129.1) with Microsoft SMTP Server (TLS) id 8.1.177.2; Tue, 11 Sep 2007 13:51:32 +0100
Received: from EA-EXMSG-C307.europe.corp.microsoft.com ([65.53.221.50]) by dub-exhub-c302.europe.corp.microsoft.com ([65.53.213.92]) with mapi; Tue, 11 Sep 2007 13:51:32 +0100
From: Stefan Santesson <stefans@microsoft.com>
To: David Chadwick <d.w.chadwick@kent.ac.uk>, Stephen Kent <kent@bbn.com>
CC: "ietf-pkix@imc.org" <ietf-pkix@imc.org>
Date: Tue, 11 Sep 2007 13:51:31 +0100
Subject: RE: request for WG to adopt draft-chadwick-webdav-00.txt as a work item
Thread-Topic: request for WG to adopt draft-chadwick-webdav-00.txt as a work item
Thread-Index: Acf0Yo8NRUu77xZ9S7iqbrSKuMqWnwADQ5nA
Message-ID: <A15AC0FBACD3464E95961F7C0BCD1FF006A25BE970@EA-EXMSG-C307.europe.corp.microsoft.com>
References: <OF3876B698.C80CC9A9-ONC125734F.002F7456@frcl.bull.fr> <46E1B0B7.3080003@kent.ac.uk> <p06240511c30b2a2eae3c@[128.89.89.71]> <46E6678A.2030307@kent.ac.uk>
In-Reply-To: <46E6678A.2030307@kent.ac.uk>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by balder-227.proper.com id l8BCpbP9082477
Sender: owner-ietf-pkix@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: d185fa790257f526fedfd5d01ed9c976

David,

Everything in security is a tradeoff, but that is not an excuse to introduce new classes of threats that defeats basic security principles when there exists valid alternatives that don't.
PKI has some basic important security principles in that it leverage trust in signed objects and not in the information infrastructure. Also, when CRLs are used for revocation checking, there is an underlying principle that one or more CRL's are available with scopes that cover all issued certificate with a current validity period.

With the WebDav proposal you violate both these principles. I don't see a strong enough motivation for doing so, and I object to putting an IETF/PKIX rubberstamp on such solution
Therefore I can't support this solution to be developed within the PKIX workgroup.


Stefan Santesson
Senior Program Manager
Windows Security, Standards


> -----Original Message-----
> From: owner-ietf-pkix@mail.imc.org [mailto:owner-ietf-
> pkix@mail.imc.org] On Behalf Of David Chadwick
> Sent: den 11 september 2007 12:02
> To: Stephen Kent
> Cc: ietf-pkix@imc.org
> Subject: Re: request for WG to adopt draft-chadwick-webdav-00.txt as a
> work item
>
>
> Hi Steve
>
> As you know nearly everything in security is a tradeoff in one way or
> another. What the webdav scheme gives you is instant revocation status,
> which CRLs do not give you, but the tradeoff is having to trust the
> repository. So the schemes are fundamentally different, but I submit
> that there are many user requirements where the tradeoff of instant
> revocation is preferable to the more cryptographically protected though
> stale CRL scheme.
>
> regards
>
> David
>
>
> Stephen Kent wrote:
> >
> > David,
> >
> > I have to agree with those who have expressed some concerns about
> > security aspects of cert revocation status under the WebDAV model.  I
> > think it is a precept of current PKI models that we don't rely
> > completely on the integrity of repositories.  That's why we post
> signed
> > CRLs and why the v2 CRL has both this update and next update fields.
> We
> > are always cognizant of the possibility that even with signed data,
> the
> > data might not be fresh, and so we try to minimize the
> vulnerabilities
> > associated with our reliance on on repositories.
> >
> > Steve
> >
> >
>
> --
>
> *****************************************************************
> David W. Chadwick, BSc PhD
> Professor of Information Systems Security
> The Computing Laboratory, University of Kent, Canterbury, CT2 7NF
> Skype Name: davidwchadwick
> Tel: +44 1227 82 3221
> Fax +44 1227 762 811
> Mobile: +44 77 96 44 7184
> Email: D.W.Chadwick@kent.ac.uk
> Home Page: http://www.cs.kent.ac.uk/people/staff/dwc8/index.html
> Research Web site:
> http://www.cs.kent.ac.uk/research/groups/iss/index.html
> Entrust key validation string: MLJ9-DU5T-HV8J
> PGP Key ID is 0xBC238DE5
>
> *****************************************************************