APNIC Home APNIC Home
Info & FAQ |  Resource services |  Training |  Meetings |  Membership |  Documents |  Whois & Search |  Internet community

You're here:  Home  Mailing Lists rescert 


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Rescert] Notes from RPKI security review



At Tue, 19 Jun 2007 15:01:39 -1000, Randy Bush wrote:
> 
> > Cert contqains CRLDP (inserted by cert's issuer) telling me where to
> > look to find out if cert has been revoked.  Whom am I trusting that I
> > should not be trusting, and what makes you think I'm trusting
> > anybody's IRBE?
> 
> you just paid 25 cents to verisign

I think you just jumped to TLS trust anchor management.  Which is
indeed a mess for us at the moment because we have not yet thought it
through, but:

My original observation was also about CRLs for CMS.  We already have
a fairly carefully worked out model for trust anchor management for
our use of CMS, but it says nothing about CRLs.