Re: PKI and Relying Parties

From: Anne & Lynn Wheeler (
Date: 03/28/02

From: Anne & Lynn Wheeler <>
Date: Thu, 28 Mar 2002 13:34:10 GMT

Harold Hammond <> writes:

> This isn't about access control or about the reliability of a PKI. The simple
> question is how can one get access to up-to-date CRLs without becoming a CA.
> I want to be able to check Certificate Revocation Lists for digital certificates
> being presented at my website. I do not want to be a CA. I do not want anyone
> to be a CA on my behalf.

another way of doing it is use an enhanced RADIUS with your website
that supports digital signature in place of password or
challenge/response (aka the webserver authentication hook implements
radius ... and then radius specifies password, challenge/response or
digital signature on an account by account basis).

RADIUS repository supplies both the authentication material
(registering password, public key, etc) and the current/accrurate
authorization information.

There is some claim that CRLs are the equivalent of the 1960s revoked
account lists distributed in monthly paper booklets in the credit card
industry. This was an offline technology implementation. Offline
technology approaches (like CRLs) became obsolete when moving from an
offline paradigm to an online paradigm starting sometime in the '70s.

You don't become a CA or support CRLs ... you just have registeration
of those that you accept and their authentication material (whether
password, digital signature, challenge/response, etc).

