El grupo de trabajo PKIX del IETF es el encargado de definir los estandares
de PKI que seran utilizados en internet (RFCs). Estos estandares son la 
base de la tecnologia PKI.

Aparte del PKIX esta el ETSI (www.etsi.org) para Europa y el ISO (x.509).

La direccion web de PKIX  http://www.ietf.org/html.charters/pkix-charter.html

Adjunto la pagina web principal. Imprescindible.

Saludos
Oscar Conesa

Title: Public-Key Infrastructure (X.509) (pkix) Charter

Public-Key Infrastructure (X.509) (pkix)

Last Modified: 11-Oct-00

Chair(s):

mailto:[EMAIL PROTECTED]
mailto:[EMAIL PROTECTED]

Security Area Director(s):

mailto:[EMAIL PROTECTED]
mailto:[EMAIL PROTECTED]

Security Area Advisor:

mailto:[EMAIL PROTECTED]

Mailing Lists:

General Discussion:[EMAIL PROTECTED]
To Subscribe: [EMAIL PROTECTED]
In Body: subscribe (In Body)
Archive: http://www.imc.org/ietf-pkix

Description of Working Group:

The PKIX Working Group was established in the Fall of 1995 with the intent of developing Internet standards needed to support an X.509-based PKI. Several informational and standards track documents in support of the original goals of the WG have been approved by the IESG. The first of these standards, RFC 2459, profiles the X.509 version 3 certificates and version 2 CRLs for use in the Internet. The Certificate Management Protocol (CMP) (RFC 2510), the Online Certificate Status Protocol (OCSP) (RFC 2560), and the Certificate Management Request Format (CRMF) (RFC 2511) have been approved, as have profiles for the use of LDAP v2 for certificate and CRL storage (RFC 2587) and the use of FTP and HTTP for transport of PKI operations (RFC 2585). RFC 2527, an informational RFC on guidelines for certificate policies and practices also has been published, and the IESG has approved publication of an information RFC on use of KEA (RFC 2528) and is expected to do the same for ECDSA. Work continues on a second certificate management protocol, CMC, closely aligned with the PKCS publications and with the cryptographic message syntax (CMS) developed for S/MIME. A roadmap, providing a guide to the growing set of PKIX document, is also being developed as an informational RFC.

The working group is now embarking on additional standards work to develop protocols that are either integral to PKI management, or that are otherwise closely related to PKI use. Work is ongoing on alternative certificate revocation methods. There also is work defining conventions for certificate name forms and extension usage for "qualified certificates," certificates designed for use in (legally binding) non-repudiation contexts. Finally, work is underway on protocols for time stamping and data certification. These protocols are designed primarily to support non-repudiation, making use of certificates and CRLs, and are so tightly bound to PKI use that they warrant coverage under this working group.

Additional work will be initiated on a profile for X.509 attribute certificates, resulting in a new RFC and, perhaps, in extensions to existing certificate management standards to accommodate differences between attribute certificates and public-key certificates.

Goals and Milestones:

Sep 99    Update RFC 2459, in anticipation of progression from PROPOSED to DRAFT
Sep 99    Complete approval of CMC, and qualified certificates documents
Dec 99    Update March/April RFCs, for progress from PROPOSED to DRAFT
Dec 99    Complete time stamping document
Dec 99    Continue attribute certificate profile work
Dec 99    Complete data certification document
Mar 00    Complete work on attribute certificate profile

Internet-Drafts:

Internet X.509 Public Key Infrastructure Time Stamp Protocols (TSP) (51692 bytes)
Internet X.509 Public Key Infrastructure Data Validation and Certification Server Protocols (108658 bytes)
Internet X.509 Public Key Infrastructure PKIX Roadmap (122090 bytes)
An Internet Attribute Certificate Profile for Authorization (86945 bytes)
Internet X.509 Public Key Infrastructure Operational Protocols - LDAPv3 (13827 bytes)
Simple Certificate Validation Protocol (SCVP) (48119 bytes)
Limited AttributeCertificate Acquisition Protocol (29006 bytes)
Internet X.509 Public Key Certificate Infrastructure and CRL Profile (260782 bytes)
Internet X.509 Public Key Infrastructure Technical Requirements for a non-Repudiation Service (21374 bytes)
Internet X.509 Public Key Infrastructure Qualified Certificates Profile (67842 bytes)
Internet X.509 Public Key Infrastructure Certificate Management Protocols (181649 bytes)
Internet X.509 Public Key Infrastructure Permanent Identifier (17752 bytes)
Transport Protocols for CMP (22474 bytes)
Internet X.509 Public Key Infrastructure Additional LDAP Schema for PKIs and PMIs (39626 bytes)
Internet X.509 Public Key Infrastructure Repository Locator Service (7288 bytes)
Internet X.509 Public Key Infrastructure Representation of Public Keys and Digital Signatures in Internet X.509 Public Key Infrastructure Certificates (56764 bytes)
Delegated Path Validation (8211 bytes)
Online Certificate Status Protocol, version 2 (43650 bytes)
Delegated Path Discovery with OCSP (8618 bytes)

Request For Comments:

Internet X.509 Public Key Infrastructure Certificate and CRL Profile (RFC 2459) (278438 bytes)
Internet X.509 Public Key Infrastructure Certificate Management Protocols (RFC 2510) (158178 bytes)
Internet X.509 Certificate Request Message Format (RFC 2511) (48278 bytes)
Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework (RFC 2527) (91860 bytes)
Internet X.509 Public Key Infrastructure Representation of Key Exchange Algorithm (KEA) Keys in Internet X.509 Public Key Infrastructure Certificates (RFC 2528) (18273 bytes)
Internet X.509 Public Key Infrastructure Operational Protocols - LDAPv2 (RFC 2559) (22894 bytes)
Internet X.509 Public Key Infrastructure Operational Protocols: FTP and HTTP (RFC 2585) (14813 bytes)
Internet X.509 Public Key Infrastructure LDAPv2 Schema (RFC 2587) (15096 bytes)
X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP (RFC 2560) (43243 bytes)
Certificate Management Messages over CMS (RFC 2797) (103357 bytes)
Diffie-Hellman Proof-of-Possession Algorithms (RFC 2875) (45231 bytes)

IETF Secretariat - Please send questions, comments, and/or suggestions to [EMAIL PROTECTED].

Return to working group directory.

Return to IETF home page.

Responder a