[78152] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: OT: SSL certificate chain problems

daemon@ATHENA.MIT.EDU (Peter Gutmann)
Tue Jan 30 11:21:58 2007

X-Original-To: cryptography@metzdowd.com
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: cryptography@metzdowd.com, Victor.Duchovni@MorganStanley.com
In-Reply-To: <20070126164258.GG11368@piias899.ms.com>
Date: Sat, 27 Jan 2007 14:12:34 +1300

Victor Duchovni <Victor.Duchovni@MorganStanley.com> writes:

>Wouldn't the old root also (until it actually expires) verify any
>certificates signed by the new root? If so, why does a server need to send
>the new root?

Because the client may not have the new root yet, and when they try and verify
using the expired root the verification will fail.

(There's a lot of potential further complications in there that I'm going to
 spare people the exposure to, but that's the basic idea).

Peter.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post