[78152] in cryptography@c2.net mail archive
Re: OT: SSL certificate chain problems
daemon@ATHENA.MIT.EDU (Peter Gutmann)
Tue Jan 30 11:21:58 2007
X-Original-To: cryptography@metzdowd.com
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: cryptography@metzdowd.com, Victor.Duchovni@MorganStanley.com
In-Reply-To: <20070126164258.GG11368@piias899.ms.com>
Date: Sat, 27 Jan 2007 14:12:34 +1300
Victor Duchovni <Victor.Duchovni@MorganStanley.com> writes:
>Wouldn't the old root also (until it actually expires) verify any
>certificates signed by the new root? If so, why does a server need to send
>the new root?
Because the client may not have the new root yet, and when they try and verify
using the expired root the verification will fail.
(There's a lot of potential further complications in there that I'm going to
spare people the exposure to, but that's the basic idea).
Peter.
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com