[TLS] AIA cert fetching seen as harmful
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[TLS] AIA cert fetching seen as harmful



Mike wrote, On 2008-04-10 09:01:

> This could be made safe with some help from PKIX (if X.509 doesn't
> already support it -- I haven't read RFC 3280 or -bis in a while).
> If root certificates listed constraints on what constitutes a valid
> URL for retrieving issued certificates, then a server could scan
> the combined list from each trusted root to determine if it is safe
> to fetch a client certificate.

Are you all aware of this paper, now making a stir?

    https://www.cynops.de/techzone/http_over_x509.html

It claims that fetching CA certs from URLs found in AIA extensions in certs
that have not yet been validated is a vulnerability.  At least one browser
organization known to me agrees.

_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.