Instant certificate revocation and publication using WebDAV

被引:2
作者
Chadwick, David [1 ]
Antony, Sean [1 ]
Bjerk, Rune [1 ]
机构
[1] Univ Kent, Comp Lab, Canterbury CT2 7NF, Kent, England
关键词
Revocation; CRLs; LDAP; HTPP; WebDAV; X.509;
D O I
10.3233/JCS-2009-0372
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There are several problems associated with the current ways that certificates are published and revoked. This paper discusses these problems, and then proposes a solution based on the use of WebDAV, an enhancement to the HTTP protocol. The proposed solution provides instant certificate revocation, minimizes the processing costs of the certificate issuer and relying party, and eases the administrative burden of publishing certificates and certificate revocation lists (CRLs). We describe how WebDAV can be used for X.509 certificate revocation, and describe how we have implemented it in the PERMIS authorization infrastructure.
引用
收藏
页码:475 / 496
页数:22
相关论文
共 18 条
[1]   From gridmap-file to VOMS: managing authorization in a Grid environment [J].
Alfieri, R ;
Cecchini, R ;
Ciaschini, V ;
dell'Agnello, L ;
Frohner, A ;
Lorentey, K ;
Spataro, E .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2005, 21 (04) :549-558
[2]  
ALLEN C., 1999, RFC 2246
[3]  
Bray T., NAMESPACES XML WORLD
[4]   Deficiencies in LDAP when used to support PKI [J].
Chadwick, D .
COMMUNICATIONS OF THE ACM, 2003, 46 (03) :99-104
[5]   PERMIS: a modular authorization infrastructure [J].
Chadwick, David ;
Zhao, Gansen ;
Otenko, Sassa ;
Laborde, Romain ;
Su, Linying ;
Nguyen, Tuan Anh .
CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2008, 20 (11) :1341-1357
[6]   Role-based access control with X.509 attribute certificates [J].
Chadwick, DW ;
Otenko, A ;
Ball, E .
IEEE INTERNET COMPUTING, 2003, 7 (02) :62-69
[7]  
Fielding Roy T., 1999, 2616 RFC
[8]  
GOLAND Y, 1999, 2518 RFC
[9]   Deploying and using public key technology: Lessons learned in real life [J].
Guida, R ;
Stahl, R ;
Bunt, T ;
Secrest, G ;
Moorcones, J .
IEEE SECURITY & PRIVACY, 2004, 2 (04) :67-71
[10]  
Gulbrandsen Arnt, 2000, 2782 RFC