Subject: Policy-Discussion
List archive
- From: Michael Tänzer <michael.taenzer AT cacert.org>
- To: cacert-policy AT lists.cacert.org
- Cc: Ian G <iang AT cacert.org>
- Subject: Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments
- Date: Thu, 17 Nov 2011 00:34:10 +0100
- Authentication-results: lists.cacert.org; dkim=pass (1024-bit key) header.i= AT cacert.org; dkim-asp=none
- Openpgp: id=9940BEF1
Hi Ian,
On 16.11.2011 23:00, Ian G wrote:
> crlDistributionPoints=URI:<crlUri>
>
> following on from discussions in NewRootsTaskForce we have surmised
> whether to get rid of CRLs in the future, as OCSP gives us a much
> better mechansim to deal with disaster recovery.
>
> But this would also involve dropping CRLs. And not putting the URI
> in the certs.
We can still drop them and stop putting URLs in the certs once we really
want to get rid of CRLs.
> Whether this is a good thing or a bad thing I'm unsure, but I note
> that Baseline Requirements (Draft 50, which has just come out 2 hours
> ago) goes some way in this direction.
>
> http://www.gerv.net/temp/Baseline_Requirements_Draft_50.pdf section
> 13.2.2. OCSP is like SHALL, and CRLs are like an IF. Although the
> text is typically unclear....
So this is basically something CAs and major browser vendors agreed upon.
a) It looks like yet another standard no one ever needed to replace the
huge load of standards we already have but really just adding another
one https://www.xkcd.com/927/
b) It's not even a standard yet. And even once it is formally accepted a
real standard is one which is widely adopted not something some
committee agreed upon (even if there are representatives of major
companies that doesn't mean they will all stick to the standard
immediately and some might even never conform to it)
c) There is a huge load of software that needs to handle certificates
and is not a browser. Just look at the other end of the connection for
example. AFAIK the openssl module for Apache only allows to specify CRLs
it will not do OCSP lookups. That might even be impossible because the
server is configured in a way that doesn't allow outgoing connections. A
cron job might update that CRL regularly. CRLs have been around for like
forever while OCSP is a relatively new thing. If we are discussing about
allowing small key sizes we definitely should keep CRLs for the sake of
backwards compatibility.
So while dropping CRLs might be possible in the future I would
definitely keep them for now.
Cheers,
--
Michael Tänzer
CAcert Support Team Leader
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, (continued)
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, J. Steijlen, 11/14/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Jan Dittberner, 11/14/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Raoul Xavier Boerlage, 11/14/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Guillaume ROMAGNY, 11/14/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Bernhard Fröhlich, 11/15/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Lambert Hofstra, 11/15/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Martin Gummi, 11/24/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, hlehmbruch, 11/25/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Martin Gummi, 11/24/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Lambert Hofstra, 11/15/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, INOPIAE (Marcus), 11/16/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Ian G, 11/16/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Michael Tänzer, 11/16/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Ian G, 11/17/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Michael Tänzer, 11/17/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Ian G, 11/17/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Michael Tänzer, 11/16/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Sören Kornetzki, 11/17/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Bernd Jantzen, 11/20/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Morten Gulbrandsen (Java programmer), 11/20/2011
- Voting time extended: Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Michael Tänzer, 11/20/2011
- Re: Voting time extended: Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Andreas Bäß, 11/25/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Werner Dworak, 11/25/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Philipp Dunkel, 11/25/2011
- Re: p20111113 CPS #7.1.2 "Certificate Extensions" adjustments, Alexander Prinsier, 11/27/2011
Archive powered by MHonArc 2.6.16.