Abstract
The central goal of Public Key Infrastructure (PKI) is to enable trust judgments between distributed users. Although certificates play a central role in making such judgments, a PKI’s users need more than just knowledge of certificates. Minimally, a relying party must able to locate critical parameters such the certificate repositories and certificate validation servers relevant to the trust path under consideration. Users in other scenarios may require other resources and services.
Surprisingly, locating these resources and services remains a largely unsolved problem in real-world X.509 PKI deployment. In this paper, we present the design and prototype of a new and flexible solution for automatic discovery of the services and data repositories are available from a Certificate Service Provider (CSP). This contribution will take real-world PKI one step closer to achieving its goal.
The authors would like to thank Stephen Kent, Frank Pooth, Ashad Noor, Sravan and all the PKIX WG for several discussions and comments. This work was supported in part by the NSF (under grant CNS-0448499 ), the U.S. Department of Homeland Security (under Grant Award Number 2006-CS-001-000001), and Sun. The views and conclusions contained in this document are those of the authors and should not be interpreted as necessarily representing the official policies, either expressed or implied, of any of the sponsors.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Myers, M., Ankney, R., Malpani, A., Galperin, S., Adams, C.: Online Certificate Status Protocol - OCSP. Internet Engineering Task Force: RFC 2560 (June 1999)
Wahl, M., Howes, T., Kille, S.: Lightweight Directory Access Protocol (v3). Internet Engineering Task Force: RFC 2251 (December 1997)
Freeman, T., Housley, R., Malpani, A., Cooper, D., Polk, W.: Server-based Certificate Validation Protocol (SCVP). IETF Draft (January 2007). [Online] Available http://www.ietf.org/internet-drafts/draft-ietf-pkix-scvp-31.txt
OpenSSL Homepage. [Online] Available: http://www.openssl.org/
OpenCA Project Homepage. [Online] Available: http://www.openca.org/
OpenCA OCSPD. [Online] Available: http://www.openca.org/ocspd/
World List of Universities. [Online] Available: http://www.unesco.org/iau/
Universities Worldwide. [Online] Available: http://univ.cc/
Hanna, S.: Follow-up Survey on Obstacles to PKI Deployment and Usage (October 2003). [Online] Available: http://www.oasis-open.org/committees/pki/pkiobstaclesaugust2003surveyreport.pdf
Housley, R., Polk, W., Ford, W., Solo, D.: Certificate and Certificate Revocation List (CRL) Profile. Internet Engineering Task Force: RFC 3280 (2002)
Mockapetris, P.: Domain Names - Implementation and Specification. Internet Engineering Task Force: RFC 1035, Request for Comments (November 1987)
Gulbrandsen, A., Vixie, P., Esibov, L.: A DNS RR for specifying the location of services (DNS SRV). Internet Engineering Task Force: RFC 2782 (February 2000)
Boeyen, S., Hallam-Baker, P.: Internet X.509 Public Key Infrastructure Repository Locator Service. IETF Experimental (September 2005). [Online] Available: http://tools.ietf.org/wg/pkix/draft-ietf-pkix-pkixrep/draft-ietf-pkix-pkixrep-04.txt
Curbera, F., Duftler, M., Khalaf, R., Nagy, W., Mukhi, N., Weerawarana, S.: Unraveling the Web Services Web: An Introduction to SOAP, WSDL, and UDDI. IEEE Internet Computing 6(2), 86–93 (2002). [Online] Available: http://dx.doi.org/10.1109/4236.991449
Martin, G., Marc, H., Noah, M., Jean-Jacques, M., Henrik Frystyk, N.: SOAP Version 1.2. W3C Recommendation (June 2003). [Online] Available: http://www.w3.org/TR/
Christensen, E., Curbera, F., Meredith, G., Weerawarana, S.: PWeb Services Description Language (WSDL) 1.1. W3C Note (March 2001). [Online] Available: http://www.w3.org/TR/2001/NOTE-wsdl-20010315
Chinnici, R., Gudgin, M., Moreau, J.-J., Weerawarana, S.: Web Services Description Language (WSDL) Version 2.0 Part 1: Core Language. W3C Working (May 2005). [Online] Available: http://www.w3.org/TR/wsdl20
Clement, L., Hately, A., von Riegen, C., Rogers, T.: UDDI Version 3.0.2. [Online] Available (October 2004), http://uddi.org/pubs/uddi_v3.htm
Common Object Request Broker Architecture: Core Specification (March, 2004), [Online] Available: http://www.omg.org/technology/documents/corba_spec_catalog.htm
Yergeau, F., Cowan, J., Bray, T., Paoli, J., Sperberg-McQueen, C.M., Maler, E.: Extensible Markup Language (XML) 1.1. W3C Recommendation (2004, February). [Online] Available: http://www.omg.org/technology/documents/corba_spec_catalog.htm
Information Technology - ASN.1 encoding rules: Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER)ITU-T Recommendation X.690 (1994) | ISO/Uniform Resource Locators (URL)IEC 8825-1:1995 (1994)
Information Technology - ASN.1 encoding rules: Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER)ITU-T Recommendation X.690 (1994) | ISO/Uniform Resource Locators (URL)IEC 8825-1:1995 (1994)
Edwards, W.: Core Jini, 2nd edn. Prentice-Hall, Englewood Cliffs (2000)
Arnold, K.: The Jini Specification, 2nd edn. Addison-Wesley, Reading (2000)
Universal Plug and Play Specifications. [Online] Available: http://www.upnp.org/resources/specifications.asp
Jenronimo, M., Weast, J.: UPnP Design by Example: A Software Developer’s Guide to Universal Plug and Play (2003)
Guttman, E., Perkins, C., Veizades, J., Day, M.: Service Location Protocol, version 2. Internet Engineering Task Force: RFC 2608 (June 1999)
Guttman, E., Perkins, C., Kempf, J.: Service Templates and Schemes. Internet Engineering Task Force: RFC 2609 (June 1999)
Guttman, E.: Service Location Protocol: Automatic Discovery of IP Network Services. IEEE Internet Computing 3(4), 71–80 (1999)
Java RMI Specification (2003). [Online] Available: http://java.sun.com/j2se/1.4.2/docs/guide/rmi/spec/rmiTOC.html
Goland, Y., Cai, T., Leach, P., Gu, Y., Albright, S.: Simple Service Discovery Protocol. IETF Draft (October 1999). [Online] Available: http://www.ietf.org/internet-drafts/draft-cai-ssdp-v1-03.txt
OpenSLP Project. [Online] Available: http://www.openspl.org
International Grid Trust Federation. [Online] Available: http://www.gridpma.org
Education Roaming (Eduroam) Homepage. [Online] Available: http://www.eduroam.org/
Author information
Authors and Affiliations
Editor information
Rights and permissions
Copyright information
© 2007 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Pala, M., Smith, S.W. (2007). AutoPKI: A PKI Resources Discovery System. In: Lopez, J., Samarati, P., Ferrer, J.L. (eds) Public Key Infrastructure. EuroPKI 2007. Lecture Notes in Computer Science, vol 4582. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-73408-6_11
Download citation
DOI: https://doi.org/10.1007/978-3-540-73408-6_11
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-73407-9
Online ISBN: 978-3-540-73408-6
eBook Packages: Computer ScienceComputer Science (R0)