[TLS] How to Validate Servers' Identities w/out reliable source of time

2018-10-04 Thread Dr. Pala
Hi all, I am struggling with one issue that we have been seeing more and more often with the introduction of small IoT devices that connect to clouds via TLS and need to validate the cloud server's (or the other party's) certificate chain. In particular, the problem is that without a reliabl

[TLS] New I-D for OCSP over DNS

2017-10-27 Thread Dr. Pala
Hello all, As suggested by some people from other WGs, I just wanted to cross-post this message here since the proposal heavily rely on DNS and can be leveraged in many different environments (e.g., Server and Client (browsers) authentication, document validation, IoT identities, etc.) and we