Re: SSL certificate modification

From: Anne & Lynn Wheeler (lynn@garlic.com)
Date: 10/10/02


From: Anne & Lynn Wheeler <lynn@garlic.com>
Date: Thu, 10 Oct 2002 13:55:01 GMT

Henrick Hellström <henrick.hellstrm@telia.com> writes:
> It is possible that ordinary web browsers will only verify the URI. I
> don't know. Other kinds of software would probably verify the IP
> address if present. If the client has access to a secure and trusted
> name server more fields could be verified.

or eliminate the certificate all together. a primary reason for the
existance of SSL server domain certificates is concerns abou the
integrity of the domain name infrastructure (correctly serving up
name->ip-address). The browser connects to a server (after getting
the URI->ip-address translation) and then checks that server correctly
posseses a certificate for the URI.

an issue is that certification authorities that issue SSL domain name
server certificates have to check with the authoritative agency for
domain names ... when they get an application for certification. Their
problem is that the authoritative agency for domain names is the
domain name infrastructure .... the very same domain name
infrastructure with integrity issues that gave rise to the
jistification for certificates in the first place.

some of the enhancements to the domain name infrastructure (to improve
its integrity) needed by certification authorities (so they can trust
the certified information) include things like the owner of a domain
name registering their public key at the some time they register the
domain name.

in any case, enhancements to the domain name infrastructure to improve
the integrity and trust (for purposes of the certification authority
market) also goes a long way to improving the integrity and trust for
everybody. Improving the integrity and trust of the domain name
infrastructure for everybody also negates much of the requirement for
needing SSL domain name server certificates (sort of a catch-22, isn't
it).

Furthermore, one of the solutions from the certification authorities
to have public keys registered as part of domain name registrtation
means that a trusted domain name infrastructure can serve up trusted
public keys in the same way that they would serve up trusted
ip-addresses.

The implementation of domain name infrastructure already supports
serving up arbritrary information, not just domain names ->
ip-addresses. Such an infrastructure would result in near real-time
trusted public keys bound to domain names (as well as any other
information that might be of interested) as opposed to the method of
stale trustetd information implemented by (the now superfulous and
redundant) SSL domain name server certificates.

random refs:
http://www.garlic.com/~lynn/subtopic.html#sslcerts

-- 
Anne & Lynn Wheeler   | lynn@garlic.com -  http://www.garlic.com/~lynn/ 



Relevant Pages

  • Re: schannel failure between AD CA and NT Domain
    ... The CA is showing up in the Trusted Root Certification Authorities Tab, ... Also each server has personal certificates as well. ... >> connection to the retrieve info. ...
    (microsoft.public.win2000.security)
  • Re: Certificate Services
    ... MS-KBQ298138_How to move a certification authority to another server ... In our system we have upgraded Windows 2000 infrastructure to windows 2003 ... Cerificates for new domain controllers exist in the issued certificates list. ...
    (microsoft.public.windows.server.security)
  • Re: Secure VPN access
    ... with it's security option for the client. ... After getting the VPN connection I check the Ip settings and found the ... point to the head ISP's DNS server. ... > Computer certificates for L2TP/IPSec VPN connections ...
    (microsoft.public.windows.server.sbs)
  • RE: L2TP/IPSEC site-to-site question
    ... seems more difficult on Windows and Isa 2000 mix, ... If I want to use certificates what type I have to use? ... > site-to-site VPN connection. ... > Site-to-Site VPN in ISA Server 2004 ...
    (microsoft.public.isa)
  • Re: Vista wireless using IAS and WPA-Enterprise
    ... certificates, which may be more than the limit that the IAS server can send ... on a Web site or if you use IAS in Windows Server 2003 ... Vista wireless using IAS and WPA-Enterprise ...
    (microsoft.public.windows.server.networking)