OCSP Hash Algorithm Independence - PowerPoint PPT Presentation

About This Presentation
Title:

OCSP Hash Algorithm Independence

Description:

Two parts make use of a hash function: Signature ::= SEQUENCE ... Signature algorithms. How will the client know which algorithms the responder support ... – PowerPoint PPT presentation

Number of Views:41
Avg rating:3.0/5.0
Slides: 6
Provided by: RussHo4
Learn more at: https://www.ietf.org
Category:

less

Transcript and Presenter's Notes

Title: OCSP Hash Algorithm Independence


1
OCSP Hash Algorithm Independence
  • Summary of Russ Housleys presentation and way
    forward.
  • Stefan Santesson

2
Request Independence Okay
  • Two parts make use of a hash function
  • Signature SEQUENCE
  • signatureAlgorithm AlgorithmIdentifier,
  • signature BIT STRING,
  • certs 0 EXPLICIT SEQUENCE OF Certificate
    OPTIONAL
  • CertID SEQUENCE
  • hashAlgorithm AlgorithmIdentifier,
  • issuerNameHash OCTET STRING,
  • issuerKeyHash OCTET STRING,
  • serialNumber CertificateSerialNumber

3
Issues
  • CertID
  • SHA-1 is fine for certID. Randomness property
    only requirement.
  • Signature algorithms
  • How will the client know which algorithms the
    responder support
  • How will the responder know which algorithms the
    client support

4
AD position
  • OCSP will not progress to draft standard until
    this issue is resolve.
  • Resolving this issue requires the WG to either
  • Define a query / response solution or,
  • Come up with a rationale for an alternative
    approach.
  • Way forward?

5
Possible Solutions
  • OOB configurations
  • Discover learn and cache
  • Capability declaration in certificates
  • Query / response expansion
Write a Comment
User Comments (0)
About PowerShow.com