A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Public Notary Transparency Working Group of
the IETF.
Title : Threat Analysis for Certificate Transparency
Author : Stephen Kent
Filename : draft-ietf-trans-threat-analysis-00.txt
Pages : 18
Date : 2015-06-02
Abstract:
This document describes a threat model for the Web PKI context in
which security mechanisms to detect mis-issuance of web site
certificates will be developed. The threat model covers both
syntactic and semantic mis-issuance, using a taxonomy of threats
starting with whether the mis-issuance was done by the CA
maliciously or not; then whether or not the certificate was logged;
and then whether the log(s) or monitor(s) are benign or malicious,
whether the certificate subject is self-monitoring and whether a
client is doing any checks.
The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-trans-threat-analysis/
There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-trans-threat-analysis-00
Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.
Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/
_______________________________________________
Trans mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/trans