[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: request for WG to adopt draft-chadwick-webdav-00.txt as a work item




David,

I have to agree with those who have expressed some concerns about security aspects of cert revocation status under the WebDAV model. I think it is a precept of current PKI models that we don't rely completely on the integrity of repositories. That's why we post signed CRLs and why the v2 CRL has both this update and next update fields. We are always cognizant of the possibility that even with signed data, the data might not be fresh, and so we try to minimize the vulnerabilities associated with our reliance on on repositories.

Steve