[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] TLS document status update
At Tue, 29 Apr 2008 17:25:02 -0700,
Mike wrote:
>
> >> There is the problem of the client knowing when its certificate is
> >> updated and that it should retrieve a new copy to recalculate the
> >> hash. It could keep track of its own validity period, but that
> >> complicates things, and wouldn't work if the CA decides to reissue
> >> a certificate early.
> >
> > Polling occasionally hardly seems like an insuperable barrier.
>
> Another problem is if the client merely polls the URL to obtain the
> certificate to calculate the hash without verifying that the cert.
> is correct. And how can it know if the certificate is correct w/o
> having its own copy?
Huh?
The client has been configured with the URL for the CA. It can also
be configured with the expected DN and the CA's public key.
-Ekr
_______________________________________________
TLS mailing list
TLS@xxxxxxxx
https://www.ietf.org/mailman/listinfo/tls