Re: [TLS] TLS document status update
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] TLS document status update



At Tue, 29 Apr 2008 17:25:02 -0700,
Mike wrote:
> 
> >> There is the problem of the client knowing when its certificate is
> >> updated and that it should retrieve a new copy to recalculate the
> >> hash.  It could keep track of its own validity period, but that
> >> complicates things, and wouldn't work if the CA decides to reissue
> >> a certificate early.
> > 
> > Polling occasionally hardly seems like an insuperable barrier.
> 
> Another problem is if the client merely polls the URL to obtain the
> certificate to calculate the hash without verifying that the cert.
> is correct.  And how can it know if the certificate is correct w/o
> having its own copy?

Huh?

The client has been configured with the URL for the CA. It can also
be configured with the expected DN and the CA's public key.

-Ekr

_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.