[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
CRL versys short-expiry
At 04:50 PM 8/7/96 -0500, Brian M. Thomas wrote:
>Subject: Re: CRL format revision -Reply
>I think that many agree. Three basic methods are available: CRLs,
>real-time validation, and short expiry
I think there are only 2 -- since I take real-time validation to be a very
short expiry. We can't have a validity period of 0 -- because there are
issues of communication time and clock skew. We can't trust a connection to
the issuer not to be delayed by an attacker, so we have to base our
decisions on date and time.
- Carl
+--------------------------------------------------------------------------+
|Carl M. Ellison cme@cybercash.com http://www.clark.net/pub/cme |
|CyberCash, Inc. http://www.cybercash.com/ |
|207 Grindall Street PGP 2.6.2: 61E2DE7FCB9D7984E9C8048BA63221A2 |
|Baltimore MD 21230-4103 T:(410) 727-4288 F:(410)727-4293 |
+--------------------------------------------------------------------------+