Presentation is loading. Please wait.

Presentation is loading. Please wait.

PKI Artifact Retention March 2006. Purpose Current drafts are silent on how refreshed timestamp chains will be verified –i.e., from where will the various.

Similar presentations


Presentation on theme: "PKI Artifact Retention March 2006. Purpose Current drafts are silent on how refreshed timestamp chains will be verified –i.e., from where will the various."— Presentation transcript:

1 PKI Artifact Retention March 2006

2 Purpose Current drafts are silent on how refreshed timestamp chains will be verified –i.e., from where will the various artifacts be obtained? Serves as a directory-focused companion to the SCVP/ERS Internet-Draft submitted last Fall

3 Mechanics Defines crossCertificatePair-like structures to bind EvidenceRecords to certificates and CRLs –HistoricalCertificate and HistoricalCRL Defines RFC2587-like object classes and attributes to contain the new structures

4 Revocation Information Appendix Provides an alternative to the X.509 expiredCertsOnCRL extension –Enables cumulative CRLs to be used to validate any certificate issued during a large time interval (up to validity of the CA) using typical logic (i.e., thisUpdate < time of interest < nextUpdate)

5 Question Should drafts of this sort be addressed by this working group? –Not in the original charter but potentially useful supporting specifications for verifying EvidenceRecords and archived digital signatures


Download ppt "PKI Artifact Retention March 2006. Purpose Current drafts are silent on how refreshed timestamp chains will be verified –i.e., from where will the various."

Similar presentations


Ads by Google