第3 章 電子認証技術に関する国際動向

Similar documents
/02/ /09/ /05/ /02/ CA /11/09 OCSP SubjectAltName /12/02 SECOM Passport for Web SR

/07/ /10/12 I

<4D F736F F F696E74202D B F8089BB82CC88EA91A496CA C982A882AF82E9504B4982CC8FF38BB52E707074>

untitled

はじめに

untitled

PKIの標準化動向と リソースPKI

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

untitled

YMS-VPN1_User_Manual

楕円曲線暗号の整備動向 +楕円暗号の実装状況

Challenge PKI 2002 IETF PKI

3. RIR 3.1. RIR Regional Internet Registry APNIC Asia Pacific Network Information Centre RIR RIPE NCC Réseaux IP Européens Network Coordination Centre

, Evaluation of Certificate Verification Methods in Mobile Environment Katsuyuki UMEZAWA,, Mitsuhiro OIKAWA, Seiichi SUSAKI, Satoru TEZUKA, and Shigei

untitled

XMLを基盤とするビジネスプロトコルの動向

1. PKI (EDB/PKI) (Single Sign On; SSO) (PKI) ( ) Private PKI, Free Software ITRC 20th Meeting (Oct. 5, 2006) T. The University of Tokush

Microsoft Intune MDM ソリューション向けDigiCert® 統合ガイド

2

untitled

Web 関連 グリー株式会社後藤 2015/12/8 IETF 94 報告会

untitled

ENUM

DNSSEC の仕組みと現状 平成 22 年 11 月 DNSSEC ジャパン

証明書検証サーバ

電子メールのセキュリティ

Enhancements In Certificate Service

ENUM トライアルジャパン 第3次報告書

Oracle Identity Managementの概要およびアーキテクチャ

ISOC-JP_IETF87_SEC_KannoRev4.pptx

Katsuhito Asano Fujitsu LTD /Apr/2002 1


Testing XML Performance


RPKI in DNS DAY

WS-I Basic Profile 1.0 の概説

untitled

RPKIとインターネットルーティングセキュリティ

sp c-final

橡03_ccTLD_rev.PDF

Mobilelron® Virtual Smartphone Platform 向けDigiCert® 統合ガイド

untitled

Windows Oracle -Web - Copyright Oracle Corporation Japan, All rights reserved.

2 BIG-IP 800 LTM v HF2 V LTM L L L IP GUI VLAN.


Vol. 45 No Web ) 3) ),5) 1 Fig. 1 The Official Gazette. WTO A

橡CoreTechAS_OverView.PDF

.Net CryptoAPI 機能と利用法

NLC配布用.ppt

図解でわかるVoIPのすべて - IP電話の技術から構築まで -

スライド タイトルなし

Financial Statements 2004

"CAS を利用した Single Sign On 環境の構築"

IPv4 over IPv6技術の最新動向と標準化

Win XP SP3 Japanese Ed. NCP IPSec client Hub L3 SW SRX100 Policy base VPN fe-0/0/0 vlan.0 Win 2003 SVR /

3. /dev/urandom 1024 ~CA0/private/cakey.pem $ openssl genrsa -rand /dev/urandom -out \ private/cakey.pem 1024 Generating RSA private key

通信プロトコルの認証技術

Juniper Networks Corporate PowerPoint Template

Motivation 3 Motivation 4 (Availability) Keep High Availability Providing Reliable Service (New service, function) Provide new Services, with new func

1 Microsoft Windows Server 2012 Windows Server Windows Azure Hyper-V Windows Server 2012 Datacenter/Standard Hyper-V Windows Server Windo

ISO/IEC 9798プロトコルの安全性評価

RPKI関連

ENUM とは E.164 番号 (= 電話番号 ) からDNSを用いてインターネット上のアプリケーションを (URI 形式で ) 得る機構電話番号から メールアドレス (mailto:) web ページ ( SIP アドレス (sip:) 電話 (tel:) IP 電話への適用は EN

Encryption Security

Slide 1

Macintosh HD:Users:ks91:Documents:lect:nm2002s:nm2002s03.dvi

iPhone Configuration Utility

ppt

特集_03-07.Q3C

untitled

CMS長期署名プロファイル(案)

EANTC 1 CSP 2 SDN WAN Automation Engine Cisco WAN Automation Engine Cisco WAN Automation Engine Cisco WAN Automation Engine Cisco WAN Automation Engin

WP_8021X Authentication_21MAY2012

Dynamic VPN Dynamic VPN IPSec VPN PC SRX IPSec VPN SRX PC IPSec 2 Copyright 2010 Juniper Networks, Inc.

wide97.dvi

untitled

T - Telecommunication and Internet Protocol Harmonization Over Networks (TIPHON); Service and Network Management Framework; Part 1: Overview and Intro

2011 Future University Hakodate 2011 System Information Science Practice Group Report Project Name Visualization of Code-Breaking Group Name Implemati

"CAS を利用した Single Sign On 環境の構築"

25 About what prevent spoofing of misusing a session information

JPGRID-GGF0205 第 5 回 GGF 調査会 globusworld 参加報告 株式会社 SRA グローバルITサービスカンパニー開発部産業第 4グループ 平野基孝 Programs 8 Tutorial 2: Grid Services and Web Services 8 Track

Epson Print Admin




IC RDFOWL PIM DB ID GIS RFID 2 ID ID ID XML web.xml GIS,PIM G-XML OWL RDF XML WSDL REST XML ID

untitled

WS-I Basic Profile 1.0 の概説

untitled

Configuring_01

untitled

IW2001-B2 1 Internet Week 2001 ( ) Copyright 2001 All Rights Reserved, by Seiji Kumagai IW2001-B2 2 CodeRed Copyright 2001 All Rights

情報セキュリティの現状と課題

NTT Communications PowerPoint Template(38pt)

のコピー

PowerPoint プレゼンテーション

Microsoft Word - ‰Z_3_“Ł“è.doc

「暗号/情報セキュリティ」

IPSJ SIG Technical Report Vol.2015-GN-93 No.29 Vol.2015-CDS-12 No.29 Vol.2015-DCC-9 No /1/27 1,a) 1 1 LAN IP 1), 2), 3), 4), 5) [

Transcription:

3 IETF PKI TAM Trust Anchor Management

3. IETF Internet Engineering Task Force PKIX WG 3.1. IETF PKIX WG 1 2006 PKI Public-Key Infrastructure IETF PKIX WG 2007 69 IETF 70 IETF WG PKIX WG 2006 3 2 3.2. 69 IETF PKIX WG 2007 7 26 5 PKIX WG ITU-T X.509 WG Working Group - PKIX WG 1 3-1 1 IETF PKIX WG http://www.ietf.org/html.charters/pkix-charter.html 2 2006 http://www.nic.ad.jp/ja/research/200707-ca/ 75

Public-Key Public-Key Infrastructure Infrastructure (X.509) (X.509) WG WG 69 IETF 69 IETF Public-Key Public-Key Infrastructure Infrastructure (X.509) (X.509) WG WG 2007/7/26 15:10-16:10 70 2007/7/26 15:10-16:10 70 Agenda Agenda Document Status Overview Document Status Overview WG documents WG documents SCVP SCVP Subject Public Key info for ECC keys Subject Public Key info for ECC keys Related specifications and Liaison Related specifications and Liaison WebDav for certificate publication and revocation WebDav for certificate publication and revocation SCEP SCEP PRQP PRQP (Syntax for binding documents with time-stamps) (Syntax for binding documents with time-stamps) Framework on key compromise Framework on key compromise Three short fixes Three short fixes 3-1 Public-Key Infrastructure (X.509) WG 69 IETF 3-2 69 IETF 76

69 IETF PKIX PKIX WG WG RFC RFC Editor RFC RFC Editor Lightweight OCSP (Proposed Standard) Lightweight OCSP (Proposed Standard) Service Name SAN(Subject Alt Name) Service Name SAN(Subject Alt Name) IESG IESG Server-based Certificate Validation Protocol (SCVP) Server-based Certificate Validation Protocol (SCVP) RFC 3280bis RFC 3280bis CMC (3 documents) CMC (3 documents) WG WG Draft for ECDSA and DSA with SHA-2 family of hash algorithms Draft for ECDSA and DSA with SHA-2 family of hash algorithms ECC algorithms ECC algorithms Credential Selection Criteria Data Structure Credential Selection Criteria Data Structure 3-2 69 IETF PKIX WG Lightweight OCSP subjectaltname Service Name SAN IESG RFC 69 IETF RFC Editor 2008 3 Lightweight OCSP RFC5019 3 Service Name SAN RFC4985 SCVP(Server-based Certificate Validation Protocol) RFC3280 (RFC3280bis) CMC(Certificate Management over CMS) 3 IESG 2008 3 SCVP RFC5055 4 RFC3280bis CMC RFC Editor RFC3280bis IESG CRL 3 The Lightweight Online Certificate Status Protocol (OCSP) Profile for High-Volume Environments (RFC 5019) http://www.ietf.org/rfc/rfc5019.txt 4 Server-based Certificate Validation Protocol (SCVP) (RFC 5055) http://www.ietf.org/rfc/rfc5055.txt 77

WG WG Internet-Draft SCVP ECC Subject Key Info SCVP http TLS ECC Subject Key Info ML 2008 3 SCVP RFC5055 ECC Working Document Related specifications and Liaison 3-3 Related specifications and and Liaison WebDAV for certificate publication and revocation WebDAV for certificate publication and revocation WebDAV SCEP Simple WebDAV Certificate Enrollment Protocol SCEP Simple Certificate Enrollment Protocol SCEP RFC SCEP RFC Tim Polk AD PKIX CMC (Paul Tim Polk AD PKIX CMC Hoffman) informational RFC (Paul Hoffman) informational RFC PRQP PKI Resource Discovery Protocol PRQP PKI Resource Discovery Protocol URI OpenCA I-D ML URI OpenCA I-D ML PKI Disaster Recovery and Key Rollover PKI CA rollover Disaster Recovery and Key Rollover informational CA rollover RFC informational RFC Three short fixes Three experimental short fixes RFC experimental RFC subject OID WebTrust subject OID complient WebTrust complient WG WG 3-3 Related specifications and Liaison PKIX WG WebDAV PKI Disaster Recovery and Key Rollover 78

WebDAV for for certificate publication and and revocation WebDAV WebDAV Representational State Transfer (REST) Representational State Transfer (REST) URL URL CRL CRL DoS DoS https://server.dns.name/c=gb/o=university%20of%20kent https://server.dns.name/c=gb/o=university%20of%20kent /cn=david%20chadwick/ /cn=david%20chadwick/ https://server.dns.name/c=gb/o=university%20of%20kent https://server.dns.name/c=gb/o=university%20of%20kent /cn=crls/ CRL /cn=crls/ CRL 3-4 WebDAV for certificate publication and revocation WebDAV for certificate publication and revocation WebDAV LDAP URL CN Common Name URL URL WebDAV PKI Disaster Recovery and Key Rollover PKIX WG individual draft Disaster Recovery 79

PKI PKI Disaster Disaster Recovery and and Key Key Rollover CRL DoS CRL DoS Revocation Authority Attribute Revocation Autohrity Time-Stamp Authority CRL Authority Repository Attribute Autohrity Time-Stamp Authority CRL Repository individual draft WG draft PKIX WG WG individual draft WG draft PKIX WG WG 3-5 PKI Disaster Recovery and Key Rollover PKI Disaster Recovery and Key Rollover 2001 7 Joel Kazin CPS(Certificate Practice Statement) PKI Informational RFC Revocation Authority Attribute Authority (Time-stamp Authority) CRL DoS(Denial of Services) ( ) 3.3. TAM Trust Anchor Management TAM BoF 69 IETF 7 27 ( ) 70 VPN TAM BoF Web VPN 80

Carl Wallace out-of-band ( ) 3-6 3-7 TAM problem statement 81

Problem Statement Problem statement Problem statement draft-wallace-ta-mgmt-problem-statement-01 draft-wallace-ta-mgmt-problem-statement-01 trust anchor store trust anchor store draft-ietf-dnsext-trustupdate-timers draft-ietf-dnsext-trustupdate-timers trust anchor trust anchor Trust Anchor Trust Anchor rfc3280 rfc3280 OCSP OCSP 3-6 Problem Statement trust anchor store Web IPsec 82

Problem Statement trust anchor store add/remove/query trust anchor store add/remove/query oub-of-band oub-of-band trust anchor trust anchor trust anchor store trust anchor store trust anchor out-of-band fingerprint trust anchor out-of-band fingerprint trust anchor store trust anchor store disaster recovery disaster recovery trust anchor authority trust anchor store trust anchor authority trust anchor store trust anchor manager trust anchor delegation trust anchor manager trust anchor delegation 3-7 Problem Statement trust anchor store fingerprint out-of-band BoF 83

TAM TAM BoF BoF Tim Polk BoF Tim Polk WG problem statement constituency( WG problem or ) statement constituency( or ) trust anchor manager trust anchor manager " trust anchor " trust anchor APNIC Terry APNIC Terry IETF ML IETF ML WG WG 3-8 TAM BoF TAM BoF Tim Polk BoF WG Trust Anchor Management IETF WG PKIX WG 3.4. 70 IETF PKIX WG 2007 12 3 1 84

Public-Key Public-Key Infrastructure Infrastructure (X.509) (X.509) WG WG 70 IETF 70 IETF Public-Key Public-Key Infrastructure Infrastructure (X.509) (X.509) WG WG 2007/12/3 13:05-15:05 50 2007/12/3 13:05-15:05 50 Agenda Agenda WG Status and Direction WG Status and Direction PKIX WG Specifications PKIX WG Specifications Certificate and Certificate Revocation List Profile (3280bis) Certificate and Certificate Revocation List Profile (3280bis) Certificate Management Messages over CMS Certificate Management Messages over CMS Subject public key info resolution for ECC Subject public key info resolution for ECC OCSP Algorithm agility OCSP Algorithm agility Related specifications and Liaison Presentations Related specifications and Liaison Presentations Liaison statements received from ITU-T SG17 Liaison statements received from ITU-T SG17 Trust Anchor Management Protocol (TAMP) Trust Anchor Management Protocol (TAMP) Updating ASN.1 modules to 1998 syntax Updating ASN.1 modules to 1998 syntax Credential selection - Mainly a PKI problem Credential selection - Mainly a PKI problem Resource Discovery Protocol Resource Discovery Protocol 3-9 Public-Key Infrastructure (X.509) WG 70 IETF Stefan Santesson Credential selection 70 IETF PKIX WG 3-10 85

70 IETF PKIX PKIX WG WG RFC RFC RFC RFC Editor Editor Server-based Certificate Validation Protocol (SCVP) Server-based Certificate Validation Protocol (SCVP) IESG IESG RFC 3280bis RFC 3280bis CMC (3 documents) CMC (3 documents) WG WG Draft for ECDSA and DSA with SHA-2 family of hash Draft for ECDSA and DSA with SHA-2 family of hash algorithms algorithms ECC algorithms ECC algorithms 3-10 70 IETF PKIX WG Server-based Certificate Validation Protocol (SCVP) RFC Editor RFC3280bis CMC IESG 2008 3 SCVP RFC5055 RFC3280bis CMC RFC Editor PKIX WG 3-10 86

PKIX WG Subject Subject public public key key info info resolution resolution for for ECC ECC ECC (Elliptic ECC (Elliptic Curve Cryptography ) Curve Cryptography ) 12 12 RFC4055 X9.62-2005 RFC4055 RFC4055 X9.62-2005 RFC4055 OCSP OCSP Algorithm Algorithm agility agility draft-hallambaker-ocspagility-00.txt draft-hallambaker-ocspagility-00.txt ML ML 3-11 PKIX WG PKIX WG ECC RFC4055 5 X9.62-2005 6 RFC4055 OCSP Algorithm agility OCSP Open Certificate Status Protocol OCSP ITU-T PKIX WG 5 Certificate and Certificate Revocation List (CRL) Profile (RFC 4055) http://www.ietf.org/rfc/rfc4055.txt 6 ANSI X9.62-2005 Public Key Cryptography for the Financial Services Industry, The Elliptic Curve Digital Signature Algorithm (ECDSA) http://webstore.ansi.org/recorddetail.aspx?sku=ansi+x9.62%3a2005 87

PKIX WG Related Related Specifications Specifications and and Liaison Liaison Presentations Presentations Liaison statements received from ITU-T SG17 Liaison statements received from ITU-T SG17 ITU-T PKIX WG ITU-T PKIX WG streetaddress upper bound unbound streetaddress upper bound unbound bufferoverflow bufferoverflow CA CA no responsible and no mechanism no responsible and no mechanism 3-12 PKIX WG ITU-T DN Distinguished Name DN streetaddress organizationname 64 128 PKIX WG PKI bufferoverflow CA CA CA PKIX WG IETF PKIX WG 88

69 IETF BoF TAM PKIX WG PKIX WG WG ML 70 IETF PKIX WG PKIX WG Trust Trust Anchor Anchor Management Management Protocol Protocol (TAMP) (TAMP) IETF-69 TAM BoF WG IETF-69 TAM BoF WG TAM Protocol PKIX WG TAM Protocol PKIX WG Working Item Working Item ML ML Updating Updating ASN.1 ASN.1 modules modules to to 1988 1988 syntax syntax ASN.1 1988 ASN.1 ASN.1 1988 ASN.1 1998 2002 ASN.1 ANY 1998 2002 ASN.1 ANY LTANS Tobias der/ber LTANS Tobias der/ber 3-13 PKIX WG ASN.1 WG individual PKIX WG WG 2008 3 WG PKIX WG ASN.1 1998 ASN.1 2002 PKIX WG RFC 89

PKIX WG Credential Credential selection selection - - Mainly Mainly a a PKI PKI problem problem http://www.ietf.org/internet-drafts/draft-santessoncredsel-01.txt http://www.ietf.org/internet-drafts/draft-santessoncredsel-01.txt Resource Resource Discovery Discovery Protocol Protocol http http ML strow poll ML strow poll 3-14 PKIX WG Credential selection Resource Discovery Protocol Credential selection Resource Discovery Protocol http Internet-Draft ML 3.5. IETF X.509 PKIX WG PKI Trust Anchor Management 2007 PKIX WG 3 RFC3280 90

Russ Housley PKIX WG PKI PKIX WG PKI 91

92