SCVP is done? OMG...

SCVP used to stand for Simple Certificate Validation Protocol, over the many years this protocol has evolved it stopped being "Simple" thus it has now been renamed to Server-based Certificate Validation Protocol.

This protocol was first proposed back when I was at ValiCert, I even had opportunity to work on early draft submissions with Ambarish Malpani, a friend and mentor.

The basic idea behind this protocol is that instead of having the complex certificate validation logic on each client one can centralize it on a server.

IMHO this model doesn't work so well, when it started the thinking was that small devices were not capable of doing the complex validation and though that might be true when the protocol was first proposed its been 8 years (a total of 33 revisions, thats 2.9 revisions a month) since then and thats no longer the case.

The next premise of this protocol was that managing trust anchors was hard so it should be centralized, the issue with this line of thinking is that a client still needs to maintain trust and targeting configuration for SCVP servers; this is, for the most part the same problem as managing CA trust anchors.

Despite all this, I am still glad to see that this RFC has completed, having standard ways of doing things helps everyone.

Print | posted on Friday, December 07, 2007 3:16 PM

Feedback

No comments posted yet.
Title  
Name  
Email
Url
Comments   
Please add 4 and 3 and type the answer here: