Re: [pkix] Last Call: <draft-ietf-pkix-rfc2560bis-15.txt> (X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP) to Proposed Standard

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> Limitations
> ~~~~~~~~
> - Works only if attacker fraudulently issued a certificate with a serial
> that is not associated with a good certificate.


This can be remedied by using an extension in which a server providing white-list information conveys a hash of the
(genuine) certificate having this serial number. Note, that such an extension does not only exist but is already used in
the context of qualified certificates in Germany: CertHash (OID 1.3.36.8.3.13), defined in CommonPKI.

Johannes






[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]