Re: Certificate Cancellation Notices (CCN)

At 03:11 PM 4/5/97 -0500, Steven Bellovin wrote:
>The point of CRLs is to avoid the need for online services.  It's not so
>much the replication of the database that concerns me; rather, it's the
>requirement that all possible acceptors of certificates be online to do
>any processing whatsoever.

We already have an even simpler mechanism for processing certificates
offline -- certificates with no online tests and no CRLs -- just their
own validity intervals.

Offline CRLs don't magically make offline certs suddenly any more precise
than certs alone whose dates are the intersection of the cert plus CRL.

