ZHAW-Logo OAPA-Logo TAT-Logo
zurück  
Diplomarbeit 2004 (DA04): Arbeits-Archiv
 
DA Sna 04/1 - Revocation check of Certificates with CRL and OCSP based on the direct environment of the UBS AG
Studierende: Nadja Holenstein, holennad
  Colette Pfister, pfistcol

Betreuer: Andreas Steffen, sna

This work is based on the direct environment of the UBS AG. It faces the problem of the controlling and closing of the validity of certificates. The analysis of discussions of how to check if a Certificate is valid or revoked reveals two major concepts behind validation and the need for revocation of certificates. These consists of periodic revocation mechanisms such as Certificate Revocation Lists (CRLs) and online query mechanisms such as the Online Certificate Status Protocol (OCSP). Within this work we will concentrate on this two fundamental revocation concepts of periodic and online revocation. The advantage and disadvantage of the till now known mechanism are described and evaluated. Furthermore this work contains a discussion about the possibilities of how a OSCP-answer can be signed. It is important to prove to the inquirer that the OCSP-answers originate from the expected OCSP-server. During our research we came up against another protocol which has got additional functions to the ones mentioned above. This protocol is called Simple Certificate Validation Protocol (SCVP). It isn?t standard yet, but specified in a Internet-Draft. Where there aren?t any time critical inquiries to be made, the CRL?s are a good solution for the UBS environment. The strict guidelines for the usage of the signing Keys in the OCSP standard lead to a manual key management which is not practicable in UBS. However the SCVP fulfils the signed answers issue and offers more flexibility. With the result of our diploma thesis we created a proposition for a solution, which could be considered in a middle-term, as soon as the SCVP protocol is declared as standard from the IETF. Furthermore it has to be implemented on clients and servers.

zurück