pem-dev
[Top] [All Lists]

Re: (Non-PEM) self-signed certifi

1993-06-21 03:15:00
Greetings from the SC21 meeting in Yokohama, where
we discussed exactly this today.  It's my hope (and
Hoyt's) that this is now on the road to being fixed
without the silliness of a new project.

I hope Ella Gardner can confirm that Ken Rossen, who used to
work for me at BBN, attended several ANSI directory meetings and
submitted a work item to add the next update field.  

It was me.  What I submittted was a defect, which was
rejected as an enhancement.  The intention was that
it would get covered in the 1992 (now 1993) extensions,
and although the modification to CRLs does not appear in
the text that has been distributed to date, some discussion
between ISO and ITU folks today should lead to a revised
syntax for CRLs which matches the PEM CRL but which
makes "NextUpdate" optional and which renames "LastUpdate"
"ThisUpdate" or some such, and which appears in the 1993 IS.
The expectation is that PEM will make the optional field
mandatory, which should be okay.

Text in X.509 suggesting that CAs's CRLs should list
revocations known to it but of other issuers would
be struck under this proposal.  

ITU still needs to crank this through, but I'll send along the
text and details once we're finished here.
--
KENR(_at_)SHL(_dot_)COM
Systemhouse



<Prev in Thread] Current Thread [Next in Thread>