Skip to main content

Updates to X.509 Policy Validation
draft-davidben-x509-policy-graph-01

Document Type Replaced Internet-Draft (individual)
Expired & archived
Author David Benjamin
Last updated 2023-03-27
Replaced by draft-ietf-lamps-x509-policy-graph
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-ietf-lamps-x509-policy-graph
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

This document updates RFC 5280 to replace the algorithm for X.509 policy validation with an equivalent, more efficient algorithm. The original algorithm built a structure which scaled exponentially in the worst case, leaving implementations vulnerable to denial-of- service attacks.

Authors

David Benjamin

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)