[TLS] AIA cert fetching seen as harmful

Nelson B Bolyard <nelson@bolyard.com> Fri, 11 April 2008 00:46 UTC

Return-Path: <tls-bounces@ietf.org>
X-Original-To: tls-archive@ietf.org
Delivered-To: ietfarch-tls-archive@core3.amsl.com
Received: from core3.amsl.com (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id AEC573A6B2D; Thu, 10 Apr 2008 17:46:55 -0700 (PDT)
X-Original-To: tls@core3.amsl.com
Delivered-To: tls@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 1F41F3A6B2D for <tls@core3.amsl.com>; Thu, 10 Apr 2008 17:46:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.859
X-Spam-Level:
X-Spam-Status: No, score=-0.859 tagged_above=-999 required=5 tests=[AWL=0.251, BAYES_05=-1.11]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZA03wXxIIHtH for <tls@core3.amsl.com>; Thu, 10 Apr 2008 17:46:54 -0700 (PDT)
Received: from smtprelay.hostedemail.com (smtprelay0228.hostedemail.com [216.40.44.228]) by core3.amsl.com (Postfix) with ESMTP id CBDED3A6ADA for <tls@ietf.org>; Thu, 10 Apr 2008 17:46:53 -0700 (PDT)
Received: from emd2-omf01.hostedemail.com (ff-bigip1 [10.5.19.254]) by smtprelay03.hostedemail.com (Postfix) with ESMTP id B9B8DBA6EC; Fri, 11 Apr 2008 00:47:14 +0000 (UTC)
X-SpamScore: 50
X-Spamcatcher-Summary: 50, 0, 0, e14e6112c10b1158, 4d03dd85d1d55713, nelson@bolyard.com, -, RULES_HIT:152:355:379:601:967:973:988:989:1187:1260:1261:1277:1311:1313:1314:1345:1359:1437:1515:1516:1518:1534:1539:1593:1594:1676:1711:1730:1747:1766:1792:2194:2199:2393:2525:2552:2560:2563:2682:2685:2857:2859:2933:2937:2939:2942:2945:2947:2951:2954:3022:3352:3622:3865:3866:3867:3869:3870:3871:3872:3873:3874:3934:3936:3938:3941:3944:4250:4321:5007:6117:6119:6121:6122:7652:7679, 0, RBL:none, CacheIP: none, Bayesian:0.5, 0.5, 0.5, Netcheck:none, DomainCache:0, MSF:not bulk, SPF:, MSBL:none, DNSBL:none
X-Spamcatcher-Explanation:
Received: from [192.168.2.5] (c-67-164-81-7.hsd1.ca.comcast.net [67.164.81.7]) (Authenticated sender: nelson@bolyard.com) by emd2-omf01.hostedemail.com (Postfix) with ESMTP; Fri, 11 Apr 2008 00:47:14 +0000 (UTC)
Message-ID: <47FEB492.6020209@bolyard.com>
Date: Thu, 10 Apr 2008 17:45:06 -0700
From: Nelson B Bolyard <nelson@bolyard.com>
Organization: Network Security Services
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; rv:1.9pre) Gecko/2008040302 NOT Firefox/2.0 SeaMonkey/2.0a1pre
MIME-Version: 1.0
To: tls@ietf.org
References: <200804101549.m3AFnH5T008818@fs4113.wdf.sap.corp> <47FE39E7.2020209@pobox.com>
In-Reply-To: <47FE39E7.2020209@pobox.com>
Subject: [TLS] AIA cert fetching seen as harmful
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: tls-bounces@ietf.org
Errors-To: tls-bounces@ietf.org

Mike wrote, On 2008-04-10 09:01:

> This could be made safe with some help from PKIX (if X.509 doesn't
> already support it -- I haven't read RFC 3280 or -bis in a while).
> If root certificates listed constraints on what constitutes a valid
> URL for retrieving issued certificates, then a server could scan
> the combined list from each trusted root to determine if it is safe
> to fetch a client certificate.

Are you all aware of this paper, now making a stir?

    https://www.cynops.de/techzone/http_over_x509.html

It claims that fetching CA certs from URLs found in AIA extensions in certs
that have not yet been validated is a vulnerability.  At least one browser
organization known to me agrees.

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls