[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: New Version Notification for draft-ietf-ltans-ers-scvp-04



Title: RE: New Version Notification for draft-ietf-ltans-ers-scvp-04

The primary change in this version changes the handling of revocation information by passing an evidence record for each revocation information object instead of one covering the set.  The original intent was for the ER wantBack to cover any corresponding wantBack but that approach wasn't viable due to the way the certificate value is returned.  Given that this property has been lost, it's easier in practice to maintain ERs for each CRL independently vs. as a set for inclusion in a wantBack.

> -----Original Message-----
> From: IETF I-D Submission Tool [mailto:idsubmission@xxxxxxxx]
> Sent: Thursday, November 08, 2007 12:52 PM
> To: cwallace@xxxxxxxxxxxx
> Cc: ietf-ltans@xxxxxxx
> Subject: New Version Notification for draft-ietf-ltans-ers-scvp-04
>
>
> A new version of I-D, draft-ietf-ltans-ers-scvp-04.txt has
> been successfuly submitted by Carl Wallace and posted to the
> IETF repository.
>
> Filename:      draft-ietf-ltans-ers-scvp
> Revision:      04
> Title:                 Using SCVP to Convey Long-term Evidence Records
> Creation_date:         2007-11-08
> WG ID:                 ltans
> Number_of_pages: 18
>
> Abstract:
> The Simple Certificate Validation Protocol (SCVP) defines an
> extensible means of delegating the development and validation
> of certification paths to a server.  It can be used to
> support the development and validation of certification paths
> well after the expiration of the certificates in the path by
> specifying a time of interest in the past.  The Evidence
> Record Syntax (ERS) defines structures, called evidence
> records, to support non-repudiation of existence of data. 
> Evidence records can be used to preserve materials that
> comprise a certification path such that trust can be
> established in the certificates after the expiration of the
> certificates in the path and after the cryptographic
> algorithms used to sign the certificates in the path are no
> longer secure.  This document describes an application of
> SCVP to serve this purpose using the WantBack feature of SCVP
> to convey evidence records.
>                                                              
>                    
>
>
> The IETF Secretariat.
>
>