This is a static archive of the previous Open Grid Forum Redmine content management system saved from host redmine.ogf.org file /dmsf_files/27 at Thu, 03 Nov 2022 23:10:26 GMT DMSF - CAOPS WG - Open Grid Forum
  Copy

Documents / Informational / OCSP Requirements for Grids Notify

Revisions

Download

2012-06-25 05:48:00 by David Groep

OCSP Requirements for Grids

Informational/OCSP_Requirements_for_Grids.doc

While certificates have built-in lifetimes, this is insufficient: lists of revoked certificates are required by many relying parties, and should be used by every relying party, in order to eliminate lost, compromised, or otherwise-invalid certificates from use. Commercial credit and debit cards are managed in an analogous fashion. The Online Certificate Status Protocol (OCSP) is a protocol that can be used to provide this service for Grid stakeholders. OCSP is a simple query protocol, relieving its clients –also called “relying parties” through this document- of the burden of managing lists of revoked certificates. The OCSP protocol is flexible and extensible, allowing certificate validation services beyond the simple reporting of contents of certificate revocation lists (CRLs). The Grid presents considerable challenges for such a service, however. To be suitable for Grid use, OCSP services must be discoverable, fault tolerant and low latency. Grid administrators need to develop interoperability methods, “chaining” methods from one OCSP responder to another, authorized OCSP responder mechanisms for multiple CAs, and replication techniques.

0.2

None

application/msword 

423.5 kB


Document progress suspended whilst group evaluates scope

Download

2012-06-25 05:47:26 by David Groep

OCSP Requirements for Grids

Informational/OCSP Requirements for Grids.zip

While certificates have built-in lifetimes, this is insufficient: lists of revoked certificates are required by many relying parties, and should be used by every relying party, in order to eliminate lost, compromised, or otherwise-invalid certificates from use. Commercial credit and debit cards are managed in an analogous fashion. The Online Certificate Status Protocol (OCSP) is a protocol that can be used to provide this service for Grid stakeholders. OCSP is a simple query protocol, relieving its clients –also called “relying parties” through this document- of the burden of managing lists of revoked certificates. The OCSP protocol is flexible and extensible, allowing certificate validation services beyond the simple reporting of contents of certificate revocation lists (CRLs). The Grid presents considerable challenges for such a service, however. To be suitable for Grid use, OCSP services must be discoverable, fault tolerant and low latency. Grid administrators need to develop interoperability methods, “chaining” methods from one OCSP responder to another, authorized OCSP responder mechanisms for multiple CAs, and replication techniques.

0.1

None

application/zip 

412.7 kB


Document progress suspended whilst group evaluates scope

(1-2/2)

This is a static archive of the previous Open Grid Forum Redmine content management system saved from host redmine.ogf.org file /dmsf_files/27 at Thu, 03 Nov 2022 23:10:29 GMT