oss-sec mailing list archives
Re: Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday
From: Steffen Nurpmeso <steffen () sdaoden eu>
Date: Tue, 12 Mar 2024 21:54:40 +0100
Valtteri Vuorikoski wrote in <avwrjlt7heiiq64iy56v6raowqilc7ldg4ona2khtbfcl6n4mg@ay3mbinzz3fm>: |On Tue, Mar 12, 2024 at 12:28:49AM -0400, Demi Marie Obenour wrote: |> macOS, iOS, Windows, and possibly Android have system certificate |> verifiers that can handle this easily. For desktop and server Linux, |> should a CRLite package be included in system package managers? Would |> it be feasible for WebPKI and {Open,Boring,Libre}SSL to handle CRLite, |> or does this mean that NSS should be used for certificate verification? | |I have no idea whether this idea has been discussed by distros or |implementors of said libraries. Perhaps someone directly involved can |weigh in on this. | |But on the face of it, CRLite-on-the-server sounds like a pretty good |idea for users who are fine with getting only a yes/no revocation |result (as opposed to the reason code and other details present in the |full CRL) and trusting the CRLite aggregator. Getting direct and |easy-to-deploy support in popular TLS libraries would seem like a net |positive for TLS security; needing to bring in a separate library, at |least if it's a relatively weighty one like NSS, probably wouldn't get |a lot of traction. A lot of traction via push by giants should, in my opinion, be observed for DNSSEC and wonderful (imho) concepts like RFC 7250. If i understood this right the new postfix 3.9 series, when used with OpenSSL 3.2.0 and above, brings support for this TLS mechanism of the future. Unfortunately terms like "the future is now" have never been anything else but hollow words (or points to the wrong direction). I do not know which other TLS libraries support RFC 7250 either. --steffen | |Der Kragenbaer, The moon bear, |der holt sich munter he cheerfully and one by one |einen nach dem anderen runter wa.ks himself off |(By Robert Gernhardt)
Current thread:
- Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday Valtteri Vuorikoski (Mar 11)
- Re: Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday Demi Marie Obenour (Mar 12)
- Re: Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday David W. Hodgins (Mar 12)
- Re: Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday Valtteri Vuorikoski (Mar 12)
- Re: Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday Steffen Nurpmeso (Mar 12)
- Re: Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday Armin Kuster (Mar 12)
- Re: Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday Valtteri Vuorikoski (Mar 12)
- Re: Certificate policy: OCSP becomes optional and CRLs mandatory for public CAs on Friday Demi Marie Obenour (Mar 12)