Certificate Management Protocols

نویسنده

  • S. Farrell
چکیده

This document describes the Internet X.509 Public Key Infrastructure (PKI) Certificate Management Protocols. Protocol messages are defined for all relevant aspects of certificate creation and management. Note that "certificate" in this document refers to an X.509v3 Certificate as defined in [COR95, X509-AM]. The key words "MUST", "MUST NOT", "REQUIRED", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document (in uppercase, as shown) are to be interpreted as described in [RFC2119]. Adams & Farrell Expires January 2001 [Page 1] Introduction The layout of this document is as follows: Section 1 contains an overview of PKI management; Section 2 contains discussion of assumptions and restrictions; Section 3 contains data structures used for PKI management messages; Section 4 defines the functions that are to be carried out in PKI management by conforming implementations; Section 5 describes version negotiation and compatibility with RFC 2510; the Appendices specify profiles for conforming implementations and provide an ASN.1 module containing the syntax for all messages defined in this specification. Adams & Farrell Expires January 2001 [Page 2] 1 PKI Management Overview The PKI must be structured to be consistent with the types of individuals who must administer it. Providing such administrators with unbounded choices not only complicates the software required but also increases the chances that a subtle mistake by an administrator or software developer will result in broader compromise. Similarly, restricting administrators with cumbersome mechanisms will cause them not to use the PKI. Management protocols are REQUIRED to support on-line interactions between Public Key Infrastructure (PKI) components. For example, a management protocol might be used between a Certification Authority (CA) and a client system with which a key pair is associated, or between two CAs that issue cross-certificates for each other. 1.1 PKI Management Model Before specifying particular message formats and procedures we first define the entities involved in PKI management and their interactions (in terms of the PKI management functions required). We then group these functions in order to accommodate different identifiable types

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Certificate Management in Ad Hoc Networks

Various types of certificates are basic tools of modern cryptography and networks security. They are used in various protocols, in the form of public key identity certificates, binding a key to its owner or in the form of attribute certificates, being a proof of rights and capabilities of their owner. Management of certificates (creation, distribution, verification, and revocation) is dependent...

متن کامل

Internet X.509 Public Key Infrastructure Certificate Management Protocols

Status of this Memo: This document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements. Please refer to the current edition of the " Internet Official Protocol Standards " (STD 1) for the standardization state and status of this protocol. Distribution of this memo is unlimited. Abstract: This document describes the ...

متن کامل

Weighted Pushdown Systems and Trust-Management Systems

The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trustmanagement system SPKI/SDSI, the security policy is given by a set of certificates, and proofs of authorization take the form of certificate chains. The certificate-chain-discovery problem is to discover a proof of authorization for a given request. ...

متن کامل

Public Key Management in Named Data Networking

As every data is signed in Named Data Networking (NDN), public key management becomes critical. The public key management requires a well-defined certificate format and several systems and protocols to support certificate distribution and revocation. In this paper, we proposed the new NDN certificate format, discussed several approaches of serving certificates in NDN. We also discuss how to rev...

متن کامل

Cryptanalysis of Three Certificate-Based Authenticated Key Agreement Protocols and a Secure Construction

Certificate-based cryptography is a new public-key cryptographic paradigm that has very appealing features, namely it simplifies the certificate management problem in traditional public key cryptography while eliminating the key escrow problem in identity-based cryptography. So far, three authenticated key agreement (AKA) protocols in the setting of certificate-based cryptography have been prop...

متن کامل

Internet Draft C

This document describes the Internet X.509 Public Key Infrastructure (PKI) Certificate Management Protocols. Protocol messages are defined for all relevant aspects of certificate creation and management. Note that "certificate" in this document refers to an X.509v3 Certificate as defined in [COR95, X509-AM]. The key words "MUST", "MUST NOT", "REQUIRED", "SHOULD", "SHOULD NOT", "RECOMMENDED", "M...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2000