This is an excellent point. Clearly the originator of a message cannot include a CRL that hasn't been issued yet in his message, and in fact including a CRL that is widely distributed in a message is pretty good way of coarsely timestamping the message--it could not have originated prior to the date/time of the CRL that is included.
Worse yet, an entire set of CRLs up to the root authority needs to be maintained.... :-( -Ray
<Prev in Thread] | Current Thread | [Next in Thread> |
---|---|---|
|
Previous by Date: | Re: DES wonk's delite, Steve Kent |
---|---|
Next by Date: | Re: DES wonk's delite, Carl Ellison |
Previous by Thread: | Re: Non-repudiation, Steve Kent |
Next by Thread: | EDE and encrypted IV's, TCJones |
Indexes: | [Date] [Thread] [Top] [All Lists] |