pem-dev
[Top] [All Lists]

Re: Non-repudiation

1993-05-25 20:09:00

  >     This question has come up before.  In general there is not a
  > requirement for PCAs or CAs to archive CRLs forever.  Rather, the
  > moddel adopted in PEM places the burden on a user to retain the
  > necessary CRLs if non-repudiation is a concern.  However, a PCA might
  > establish CRL archive requirements if it believed that its subscribers
  > would view this as a value-added feature.
  > 
Steve,

I agree with what you said. Might this not be a reasonable argument
for allowing CRL's in the message headers? It seems to me that any
document with a lifetime would probably wish to include the current
CRL's in spite of their potential size. This scheme would also ease
the burden on the user who wished to save such things. 

                Paul


<Prev in Thread] Current Thread [Next in Thread>