CRL versys short-expiry

At 04:50 PM 8/7/96 -0500, Brian M. Thomas wrote:
>Subject: Re: CRL format revision -Reply

>I think that many agree.  Three basic methods are available: CRLs,
>real-time validation, and short expiry

I think there are only 2 -- since I take real-time validation to be a very
short expiry.  We can't have a validity period of 0 -- because there are
issues of communication time and clock skew.  We can't trust a connection to
the issuer not to be delayed by an attacker, so we have to base our
decisions on date and time.

 - Carl

