Re: PKI and Relying Parties

From: Paul Rubin (phr-n2002a@nightsong.com)
Date: 03/27/02


From: Paul Rubin <phr-n2002a@nightsong.com>
Date: 27 Mar 2002 10:35:52 -0800

Anne & Lynn Wheeler <lynn@garlic.com> writes:
> some number of financial institutions have gone to "relying party
> only" certificates ... i.e. certificates issued by the institution and
> only useful by that insitution. what they found out was that they were
> interested in public key authentication ... which (apparently when
> they started) they thought was equivalent to PKI, CAs, certificates,
> etc.
>
> What they started to find out was that the transactions & operations
> were accessing the same infrastructure that effectively was used for
> issuing the certificates ... including real time status information.
>
> It was then trivially possible to show that the actual issuance of a
> certificate as redundant and superfulous.

Yeah, that's what the whole private CA biz seems to be about (Verisign
OnSite, etc.)



Relevant Pages

  • Re: PKI and Relying Parties
    ... > some number of financial institutions have gone to "relying party ... > only" certificates ... ... > issuing the certificates ... ...
    (comp.security.misc)
  • Re: Certificates
    ... digital certificates and certification authorities are mechanisms to ... repository of trusted public keys. ... i.e. the relying party has had no prior ...
    (microsoft.public.security)
  • Re: New Method for Authenticated Public Key Exchange without Digital Certificates
    ... > certificates are in some cases not directly seen by the end ... certifying the combination of the public key contained in the public ... redundant and superfluous. ... I've repeatedly claimed that in the cases where the relying party ...
    (sci.crypt)
  • Re: Root CA issuing CA
    ... and a subordinate issuing CA. ... a certificates though the subordinate CA to client computers. ... server name resolving to the new server. ...
    (microsoft.public.windows.server.security)
  • Certificate Question
    ... You have to have a root CA and a subordinate CA. ... The issuing CA is the subordinate. ... >be using eTokens side by side with certificates for 2 ...
    (microsoft.public.win2000.security)