[78165] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: OT: SSL certificate chain problems

daemon@ATHENA.MIT.EDU (Victor Duchovni)
Tue Jan 30 11:30:50 2007

X-Original-To: cryptography@metzdowd.com
Date: Sun, 28 Jan 2007 01:08:11 -0500
From: Victor Duchovni <Victor.Duchovni@MorganStanley.com>
To: cryptography@metzdowd.com
Mail-Followup-To: cryptography@metzdowd.com
In-Reply-To: <E1HAc7O-000344-00@medusa01.cs.auckland.ac.nz>

On Sat, Jan 27, 2007 at 02:12:34PM +1300, Peter Gutmann wrote:

> Victor Duchovni <Victor.Duchovni@MorganStanley.com> writes:
> 
> >Wouldn't the old root also (until it actually expires) verify any
> >certificates signed by the new root? If so, why does a server need to send
> >the new root?
> 
> Because the client may not have the new root yet, and when they try and verify
> using the expired root the verification will fail.

I am curious how the expired trusted old root helps to verify the as
yet untrusted new root... Is there a special-case behaviour when the
old and new root share the same DN and public key? Is such special-case
behaviour standard for trust chain verification implementations (allowing
the lifetime of root CAs to be indefinitely extended by issuing new certs
with the same keys)?

-- 
	Viktor.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post