<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
	<channel>
<title>Stefan Santesson AAA-sec</title><link>http://aaa-sec.com/index.html</link><description>News</description><dc:language>en</dc:language><dc:creator>stefans@exmsft.com</dc:creator><dc:rights>Copyright 2009 3xA Security AB</dc:rights><dc:date>2011-05-11T21:18:55+02:00</dc:date><admin:generatorAgent rdf:resource="http://www.realmacsoftware.com/" />
<admin:errorReportsTo rdf:resource="mailto:stefans@exmsft.com" /><sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2000-01-01T12:00+00:00</sy:updateBase>
<lastBuildDate>Wed, 04 Mar 2009 04:13:45 +0100</lastBuildDate><item><title>Certificate image standard published as RFC 6170</title><dc:creator>stefans@exmsft.com</dc:creator><category>All&#x2c; Protocols</category><dc:date>2011-05-11T21:18:55+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/2506148b0526e4b7752d3994b932c08c-32.html#unique-entry-id-32</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/2506148b0526e4b7752d3994b932c08c-32.html#unique-entry-id-32</guid><content:encoded><![CDATA[Recently the certificate image standard developed by 3xA Security together with Russ Housley (IETF Chair), Adobe and in cooperation with VeriSign was adobted by the IETF as RFC 6170 (<a href="http://tools.ietf.org/html/rfc6170" rel="self">http://tools.ietf.org/html/rfc6170</a>).<br />]]></content:encoded></item><item><title>Microsoft supports EU Signature standard in Office 2010</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Protocols</category><dc:date>2010-04-30T09:51:19+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/7a758359ab51fdb087e1654879ee4707-31.html#unique-entry-id-31</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/7a758359ab51fdb087e1654879ee4707-31.html#unique-entry-id-31</guid><content:encoded><![CDATA[Microsoft has decided to support the EU digital signature format XAdES in Office 2010.<br /><br />Read more about this at: <a href="http://blogs.technet.com/office2010/archive/2009/12/08/digital-signitures-in-office-2010.aspx" rel="external">http://blogs.technet.com/office2010/archive/2009/12/08/digital-signitures-in-office-2010.aspx</a><br /><br />This format builds on the XML Digital signature standard from W3C which is the globally accepted standard for XML signatures.<br />]]></content:encoded></item><item><title>Internationalization - A growing pain for Internet protocol design</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Protocols</category><dc:date>2009-11-16T06:34:40+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/9c86970fcb87da6df1f269a3e3be8f58-30.html#unique-entry-id-30</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/9c86970fcb87da6df1f269a3e3be8f58-30.html#unique-entry-id-30</guid><content:encoded><![CDATA[International characters are becoming a growing pain for Internet protocol design.<br />Many protocols just deal with 7-bit ASCII on the basic protocol level while there is an increasing demand for information expression in local languages at the application layer. Various protocols like Internet mail and DNS has addressed this issue by defining conventions to carry international characters over 7-bit ASCII. The problem is rather straightforward as long as the task is limited to presentation of data in a local language context, but grows to a very hard problem when the task is expanded to comparison of canonicalized strings from different sources. The problem is even harder if consistency between visual matching and matching of encoded character strings is required.<br /><br />The technical plenary at the 76th IETF in Hiroshima (November 8-13 2009) recently focused in on this particular problem.]]></content:encoded></item><item><title>TLS Cached Info update</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Protocols</category><dc:date>2009-11-12T03:19:53+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/5bd497a98cdaf062d3386232d0e858bd-29.html#unique-entry-id-29</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/5bd497a98cdaf062d3386232d0e858bd-29.html#unique-entry-id-29</guid><content:encoded><![CDATA[I&rsquo;m currently writing a new standard for TLS which will allow the client to cache big portions of static data exchanged during TLS handshake negotiations and allow the server to omit resending this data on consecutive handshakes, such as in consecutive re-negotiations.<br /><br />My slides for the TLS meeting today at the Hiroshima IETF, showing the basic approach. is available here: <a href="http://tools.ietf.org/agenda/76/slides/tls-5.pdf">Cached Info (PDF)</a>.<br /><br /><br />]]></content:encoded></item><item><title>Null Prefix attack against TLS Server Certificates </title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Protocols</category><dc:date>2009-11-12T02:49:08+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/42ed6cd9167709ace8cb0e61511f8395-28.html#unique-entry-id-28</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/42ed6cd9167709ace8cb0e61511f8395-28.html#unique-entry-id-28</guid><content:encoded><![CDATA[A new embarrassing attack was recently discovered and exploited on Server Certificates and their validation in many current browser environments.<br /><br />The discovery is that current deployment of domain name matching between the domain expressed in the certificate and the domain protected by the certificate use string matching which treat character 00 (\0) as end of string.<br />]]></content:encoded></item><item><title>New attack against TLS</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Protocols</category><category>&#x27;</category><dc:date>2009-11-12T02:32:32+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/f54f5e42d7188c2dd5b6355b7014b8da-27.html#unique-entry-id-27</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/f54f5e42d7188c2dd5b6355b7014b8da-27.html#unique-entry-id-27</guid><content:encoded><![CDATA[The TLS workgroup in the IETF (Internet Engineering Task Force) is currently heavily engaged in finding a quick solution to the just recently discovered and published attack against TLS using TLS renegotiaion.]]></content:encoded></item><item><title>The problem of keeping a blog as expert consultant</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><dc:date>2009-09-15T11:08:21+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/b8f16511b763ae9088573e256c16d9bd-26.html#unique-entry-id-26</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/b8f16511b763ae9088573e256c16d9bd-26.html#unique-entry-id-26</guid><content:encoded><![CDATA[I have realized that there are may ways to keep a blog.<br /><br />One goal is to write something everyday regardless of whether you have anything to say or not. That is not the path i I like to choose.<br />So I like to turn here and write about things that;<br /><br /><ol class="arabic-numbers"><li>i find interesting,</li><li>i think someone else might have interest in, and;</li><li>does not violate reasonable confidentiality agreements with my customers.</li></ol><br />Unfortunately the third is quite a limiting factor. Sometimes the most interesting things at hand I would like to write about is something that my customers do not wish to have published on my blog. And that is something I have to respect.<br />]]></content:encoded></item><item><title>Man in the middle attack against Extended Validation protected Web sites</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Authentication</category><dc:date>2009-07-15T23:27:51+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/51eed15e5c72e76a760b5bf146d68834-25.html#unique-entry-id-25</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/51eed15e5c72e76a760b5bf146d68834-25.html#unique-entry-id-25</guid><content:encoded><![CDATA[Two security researchers are presenting a man in the middle attack against Extended Validation (EV) protected websites through what they term &ldquo;SSL Rebinding&rdquo;.<br />The basic problem is that modern websites combines information from many sources simultaneously when providing services to users. The problem a browser faces is to decide when it is valid to show the Extended Validation protection level by the &ldquo;green bar&rdquo;, or similar UI distinction, when only part of the visible content is provided through an EV certificate protected TLS(SSL) session.<br />Some sites, such as PayPal provide part of the content through EV protected TLS while other parts are just protected using a Domain Validation (DV) certificate, but web browsers will still regard the whole session as EV protected.<br /><br />The researchers claim to have found an attack that effectively exploits this and will present their result at the upcoming Black Hat conference.<br />]]></content:encoded></item><item><title>Minimum requiriments for electronic signatures in Europe may disqualify perfectly valid signatures</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Signatures</category><dc:date>2009-07-03T03:08:33+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/46c6b6d2884b9af82c69d7698995e114-24.html#unique-entry-id-24</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/46c6b6d2884b9af82c69d7698995e114-24.html#unique-entry-id-24</guid><content:encoded><![CDATA[Various activities in Europe tries, in light of the Services directive, to establish minimum requirements for Advanced Electronic Signatures in Europe.<br />The background of the electronic signature directive and the electronic signature standards in Europe makes this a hard and potentially dangerous task where we run a risk of disqualifying most signature capable products for no obvious gain.<span style="font:12px Cambria; "><br /></span>]]></content:encoded></item><item><title>EU Identity project turns its back on Information Card</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Authentication</category><category>Events</category><dc:date>2009-06-29T23:46:54+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/4176dc973cf2d8806754c9f567725e30-23.html#unique-entry-id-23</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/4176dc973cf2d8806754c9f567725e30-23.html#unique-entry-id-23</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">The EU Commission funded project STORK announced during its second Industry Group Meeting, that they have decided on SAML 2.0 as protocol for its technical architecture.<br />The STORK project is the primary pilot project assigned by the EU commission to test cross border electronic identification between citizens and electronic services across Europe.<br /><br />The first Industry Group Meeting resulted in feedback suggesting that the proposed architecture have potential vulnerabilities with respect to man in the middle attacks.<br />The combination of the solution to this problem and the selection of SAML 2.0 as the protocol of choice effectively prevents the use of the Information Card technology developed by the Industry during the past five years. The reason for this is that the Information Card model, which also use SAML assertions, uses WS-Trust as its primary exchange protocol and not pure SAML.<br /></span>]]></content:encoded></item><item><title>New Internet Draft Nroff editor</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><dc:date>2009-06-17T04:32:33+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/4a6155e1e5264151eb5e57e7d3131cd9-22.html#unique-entry-id-22</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/4a6155e1e5264151eb5e57e7d3131cd9-22.html#unique-entry-id-22</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">I have written and made available an Internet Draft editor for writing drafts in Nroff format.<br />The Nroff format was the dominant way to format draft and RFC documents in the past and many draft writers still use the Nroff format with some command line compiler.<br /><br />As I failed to find any decent application with which I could edit an nroff file and see the result in one application, I decided to write my own in<br /><br />NroffEdit as a Java application distributed as jar file and is prepared for Mac and Windows.<br /><br />For more information see </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://aaa-sec.com/nroffedit/index.html" rel="self">http://aaa-sec.com/nroffedit/index.html</a></span><span style="font:14px Times, Georgia, Courier, serif; "><br /><br />I appreciate any comments, feedback suggestions or bug reports.<br /></span>]]></content:encoded></item><item><title>IETF agrees to develop Visual eID standard</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Visual eID</category><category>Protocols</category><dc:date>2009-05-14T14:35:19+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/5e9f8a9fd0e2c17829a8b22cdc25db11-21.html#unique-entry-id-21</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/5e9f8a9fd0e2c17829a8b22cdc25db11-21.html#unique-entry-id-21</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">The PKIX group of the Internet Engineering Task Force has decided to adopt the work item to develop a standard for visual representation of e-identification certificates.<br /><br />The PKIX group accepted the draft proposed by the </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://aaa-sec.com/visualeid/index.html" rel="self">Visual eID project</a></span><span style="font:14px Times, Georgia, Courier, serif; "> as starting point for the standards work.<br />The current PKIX draft can be found </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://aaa-sec.com/pub/docs/drafts/draft-ietf-pkix-certimage-00.txt" rel="self">here</a></span><span style="font:14px Times, Georgia, Courier, serif; ">.</span>]]></content:encoded></item><item><title>Support the Visual eID work in PKIX</title><dc:creator>stefans@exmsft.com</dc:creator><category>Visual eID</category><category>All</category><dc:date>2009-05-04T11:11:16+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/f30de9140c7ef3cbfaef20b4b7ca9fb3-20.html#unique-entry-id-20</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/f30de9140c7ef3cbfaef20b4b7ca9fb3-20.html#unique-entry-id-20</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">The current status of the Visual eID standardisation process is for IETF to accept this work as part of its agenda.<br /><br />The Visual eID standard has been proposed to be added to the PKIX WG agenda and its acceptance is currently up for open discussion.<br />The draft standard under discussion is found at: </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://tools.ietf.org/html/draft-santesson-pkix-certimage-00" rel="self">http://tools.ietf.org/html/draft-santesson-pkix-certimage-00</a></span><span style="font:14px Times, Georgia, Courier, serif; "><br /><br />You can influence the decision in the IETF/PKIX and take part in the development discussion by posting your view at the PKIX mailing list. This list is open for anyone who wishes to attend.<br /><br />To subscribe to the PKIX mailing list send an e-mail to: </span><a href="mailto:ietf-pkix-request@imc.org?body=subscribe" rel="self">ietf-pkix-request@imc.org</a><br />In the body of the e-mail enter &ldquo;subscribe&rdquo; <br /><br />To support this work being adopted as a PKIX work item, send a mail to the PKIX mailing list:  <span style="font:10px &#39;Lucida Grande&#39;, LucidaGrande, Verdana, sans-serif; "><a href="mailto:IETF-pkix <ietf-pkix@imc.org>" rel="self">ietf-pkix@imc.org</a></span><span style="font:10px &#39;Lucida Grande&#39;, LucidaGrande, Verdana, sans-serif; "><br /><br /></span>The following message can be used:<br />&ldquo;I support adoption of draft-santesson-pkix-certimage-00 as PKIX work item&rdquo;<br /><br />Click <a href="mailto:ietf-pkix@imc.org?subject=draft-santesson-pkix-certimage-00&body=I support adoption of draft-santesson-pkix-certimage-00 as PKIX work item" rel="self">here</a> to generate a ready composed e-mail.<br />]]></content:encoded></item><item><title>SHA-1 taking a significant hit</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><category>Signatures</category><dc:date>2009-05-01T01:58:31+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/9b52c4d73c9ee910d7f1267a19dbb711-19.html#unique-entry-id-19</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/9b52c4d73c9ee910d7f1267a19dbb711-19.html#unique-entry-id-19</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">SHA-1 has taken a significant hit.<br />Recent presentation at the EuroCrypt rump session suggest that the problem to find SHA-1 collision is reduced to 2^52.<br />This is a significant reduction from the previously known best path with complexity 2^63.<br /><br />For details, see:<br /></span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://eurocrypt2009rump.cr.yp.to/837a0a8086fa6ca714249409ddfae43d.pdf" rel="self">http://eurocrypt2009rump.cr.yp.to/837a0a8086fa6ca714249409ddfae43d.pdf</a></span><span style="font:14px Times, Georgia, Courier, serif; "><br /><br /></span>]]></content:encoded></item><item><title>FIrst visual eID draft posted</title><dc:creator>stefans@exmsft.com</dc:creator><category>Visual eID</category><category>All</category><category>Protocols</category><category>Authentication</category><dc:date>2009-04-22T12:20:45+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/a6d30e7afb52749ceeb0851b143945da-18.html#unique-entry-id-18</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/a6d30e7afb52749ceeb0851b143945da-18.html#unique-entry-id-18</guid><content:encoded><![CDATA[The first IETF draft is posted:<br /><a href="http://aaa-sec.com/pub/docs/drafts/draft-santesson-pkix-certimage-00.txt" rel="self">draft-santesson-pkix-certimage-00</a><br /><br />The first draft is a result from an initial design process within the editorial team as well as discussions with partners and members of the CA Browser Forum.<br />This draft will initiate discussion in the <a href="http://tools.ietf.org/wg/pkix/" rel="self">PKIX</a> WG whether to accept this as an adopted work item.<br />]]></content:encoded></item><item><title>Scalable Image Formats</title><dc:creator>stefans@exmsft.com</dc:creator><category>Visual eID</category><category>Protocols</category><category>All</category><dc:date>2009-04-20T14:14:03+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/e3c484febea09d2a545d7cbcb88cfe98-17.html#unique-entry-id-17</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/e3c484febea09d2a545d7cbcb88cfe98-17.html#unique-entry-id-17</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">In the discussions concerning a visual image of an identity certificate, the image format of choice is a hot topic.<br /><br />The issuer of the certificate knows what the image should look like but don&rsquo;t know the type, size and resolution of the screen where it will be displayed. Therefore, what we need is a scalable image format that can render text and graphical elements. <br /><br />Choosing one image format has however turned out to be a bit problematic.<br /></span>]]></content:encoded></item><item><title>Visual eID Problem Statement posted</title><dc:creator>stefans@exmsft.com</dc:creator><category>Visual eID</category><category>Authentication</category><category>All</category><dc:date>2009-04-18T03:32:43+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/1de9acf490dfb484d8977abf1ee20f8d-16.html#unique-entry-id-16</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/1de9acf490dfb484d8977abf1ee20f8d-16.html#unique-entry-id-16</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">Based on input and discussions around the Visual eID project, I have written a problem statement which will be a living document for the project.<br />This document attempts to capture on a few pages, the basic problems and scenarios as well as the main reasons why this work is needed.<br /><br /></span><img class="imageStyle" alt="Pasted Graphic" src="http://aaa-sec.com/web/blog_files/pasted-graphic-3-6.jpg" width="180" height="96"/><span style="font:14px Times, Georgia, Courier, serif; "><br /></span><span style="font:14px Times, Georgia, Courier, serif; "><br />This living document is available </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://aaa-sec.com/pub/docs/VisualeID_ProblemStatement.pdf" rel="self">here</a></span><span style="font:14px Times, Georgia, Courier, serif; ">.<br /><br />Comments and inputs are highly appreciated.</span>]]></content:encoded></item><item><title>Visual eID submitted to ISSE 2009</title><dc:creator>stefans@exmsft.com</dc:creator><category>Visual eID</category><category>Authentication</category><category>All</category><dc:date>2009-04-03T01:55:03+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/4bdf319ad4ea32de22417e59c0c0ba2b-14.html#unique-entry-id-14</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/4bdf319ad4ea32de22417e59c0c0ba2b-14.html#unique-entry-id-14</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">The visual eID standards effort has been submitted to the Information Security Solutions Europe conference in Hague, October 2009.<br />The submitted abstract below provide some basic rationales and orientation:<br /><br /></span><span style="font:17px Times, Georgia, Courier, serif; font-weight:bold; font-weight:bold; "><u>Abstract:</u></span><br />Since the EU directive on electronic signatures was published in 1999, national certification authorities have issued millions of certificates and qualified certificate. But have you actually seen one?<br /><br />It is a paradox, considering that development of standards for electronic identification using Public Key Cryptography has been going on for a bit over 20 years by now, that we still have no generic solution or standard for how to display a certificate based identity to a human being.<br /><br />]]></content:encoded></item><item><title>Strong editorial team for visual eID standard</title><dc:creator>stefans@exmsft.com</dc:creator><category>Visual eID</category><category>Authentication</category><category>All</category><dc:date>2009-03-31T08:14:52+02:00</dc:date><link>http://aaa-sec.com/web/blog_files/cf0251b75a96e4ba680d3e6e307afaae-13.html#unique-entry-id-13</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/cf0251b75a96e4ba680d3e6e307afaae-13.html#unique-entry-id-13</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">During IETF last week in San Francisco we managed to form a really strong editorial team for the new visual eID standard.<br /><br />This standard will make it possible to bind a visual representation of a certificate to its signature. More information about this project is available on my </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://aaa-sec.com/visualeid/index.html" rel="self">Visual eID</a></span><span style="font:14px Times, Georgia, Courier, serif; "> information page.<br /><br />The editorial team:<br /><br /></span><span style="font:14px Times, Georgia, Courier, serif; font-weight:bold; font-weight:bold; ">Stefan Santesson, 3xA Security</span><span style="font:14px Times, Georgia, Courier, serif; "> is lead editor as initiator and driver of this standards effort.<br /><br /></span><span style="font:14px Times, Georgia, Courier, serif; font-weight:bold; font-weight:bold; ">Russ Housley, Vigil Security</span><span style="font:14px Times, Georgia, Courier, serif; ">. Russ is chairman of the Internet Engineering Task Force and was also co-editor of the original standard </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://tools.ietf.org/html/rfc3709" rel="self">RFC 3709</a></span><span style="font:14px Times, Georgia, Courier, serif; "> on which this standards effort is based.<br /><br /></span><span style="font:14px Times, Georgia, Courier, serif; font-weight:bold; font-weight:bold; ">Siddharth Bajaj, VeriSign</span><span style="font:14px Times, Georgia, Courier, serif; ">. VeriSign as the world leading provider of public certificates for web servers has been actively promoting a better UI experience for certificate based identification and authorisation. Siddharth has been actively involved with these efforts for almost a decade.<br /><br /></span><span style="font:14px Times, Georgia, Courier, serif; font-weight:bold; font-weight:bold; ">Leonard Rosenthol, Adobe</span><span style="font:14px Times, Georgia, Courier, serif; ">. This standards effort was made possible much thanks to the standardisation of PDF in 2008. Leonard is the standards architect behind the development of an ETSI standard for PDF based Advanced Electronic Signatures (PAdES).<br /><br />The work to write this standard will start immediately and a first draft will be published soon, no later than end of April.</span>]]></content:encoded></item><item><title>Cert Cache adopted as TLS standards work</title><dc:creator>stefans@exmsft.com</dc:creator><category>Protocols</category><category>All</category><dc:date>2009-03-26T19:26:24+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/7243b733cc1fb726b2716331e3929274-12.html#unique-entry-id-12</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/7243b733cc1fb726b2716331e3929274-12.html#unique-entry-id-12</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">Today (March 26) at the IETF 74 conference, the TLS working group decided to adopt the certificate cache work with the intention to develop this to a new TLS standard. The decision was made after my </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://aaa-sec.com/pub/docs/TLS_Cached_Certs.pdf" rel="self">presentation</a></span><span style="font:14px Times, Georgia, Courier, serif; "> of the certcache proposal at the TLS working group.<br /><br />The basic idea behind this proposal can be found in this </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://aaa-sec.com/web/blog_files/204130f4e89782f473e5957e56bf39d4-2.html" rel="self">blog</a></span><span style="font:14px Times, Georgia, Courier, serif; "> article.<br />The first draft (draft-santesson-tls-certcache-00) is available </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://tools.ietf.org/html/draft-santesson-tls-certcache-00" rel="self">here</a></span><span style="font:14px Times, Georgia, Courier, serif; "><br /></span>]]></content:encoded></item><item><title>PKIX Meeting Minutes and Presentations</title><dc:creator>stefans@exmsft.com</dc:creator><category>Events</category><category>All</category><dc:date>2009-03-25T18:32:05+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/ebc87c0f930c6bc6028c9370850fb828-11.html#unique-entry-id-11</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/ebc87c0f930c6bc6028c9370850fb828-11.html#unique-entry-id-11</guid><content:encoded><![CDATA[The PKIX group of the Internet Engineering Task Force met this Monday in San Francisco.<br />I made several presentations at this meeting but my main focus was on presenting the <a href="http://aaa-sec.com/visualeid/index.html" rel="self">Visual eID Project</a> and in particular the standards efforts that is required to form a complete technical solution.<br /><br />Meeting minutes and presentations are available from <a href="http://tools.ietf.org/wg/pkix/minutes" rel="self">http://tools.ietf.org/wg/pkix/minutes</a>]]></content:encoded></item><item><title>Visual eID project presented at PKIX&#x2c; March 23</title><dc:creator>stefans@exmsft.com</dc:creator><category>Visual eID</category><category>Authentication</category><category>All</category><dc:date>2009-03-22T02:32:08+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/60e80f6bc62fb090b7c2d479d4ff52a1-10.html#unique-entry-id-10</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/60e80f6bc62fb090b7c2d479d4ff52a1-10.html#unique-entry-id-10</guid><content:encoded><![CDATA[On Monday March 23, I will present the standards mission of the Visual eID project at the PKIX meeting at the IETF 74 in San Francisco.<br /><br />The presentation is available <a href="http://aaa-sec.com/pub/docs/visualeID.pdf" rel="self">here</a><br /><br />I&rsquo;m currently looking for partners and sponsors for this project and for this purpose I have created a project information page at <a href="http://aaa-sec.com/visualeid/" rel="self">http://aaa-sec.com/visualeid/</a>.<br /><br /><span style="font:14px Times, Georgia, Courier, serif; "> <div class="js-kit-comments" permalink=""></div></span>]]></content:encoded></item><item><title>ETSI approves new European PDF signature standard</title><dc:creator>stefans@exmsft.com</dc:creator><category>Protocols</category><category>Signatures</category><category>All</category><dc:date>2009-03-19T12:57:16+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/d80188ca17bd24848a3a90ea69caa12a-9.html#unique-entry-id-9</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/d80188ca17bd24848a3a90ea69caa12a-9.html#unique-entry-id-9</guid><content:encoded><![CDATA[The Electronic Signature Initiative group of the European Telecommunication Standards Institute, ETSI ESI, approved PAdES, the European standard for PDF Advanced Electronic Signatures on March 18, 2009.<br /><br />PAdES, or ETSI standard TS 102 778, is ETSI&rsquo;s continuation of EU commission funded standardization of Advanced Electronic Signatures in support of the <a href="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31999L0093:EN:HTML" rel="self">EU Electronic Signature Directive from 1999</a>. PAdES is the third signature standard in the ETSI series covering signatures on PDF documents. Previously published ETSI signature standards have specified signatures on XML documents (<a href="http://webapp.etsi.org/workprogram/Report_WorkItem.asp?WKI_ID=21353" rel="self">XAdES</a>) and signatures using CMS (<a href="http://webapp.etsi.org/workprogram/Report_WorkItem.asp?WKI_ID=28069" rel="self">CAdES</a>) where CMS is the ASN.1 based signature (<a href="http://tools.ietf.org/html/rfc3852" rel="self">Cryptographic Message Syntax</a>) developed by IETF as part of the <a href="http://www.ietf.org/html.charters/smime-charter.html" rel="self">S/MIME standards</a> series for secure e-mail.<br />]]></content:encoded></item><item><title>EU Commission action plan on Electronic Signatures and Electronic Identities</title><dc:creator>stefans@exmsft.com</dc:creator><category>Policy</category><category>Visual eID</category><category>All</category><dc:date>2009-03-17T16:13:15+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/574eca70f1b4f4af415e3dbdc21e5dcd-8.html#unique-entry-id-8</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/574eca70f1b4f4af415e3dbdc21e5dcd-8.html#unique-entry-id-8</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">The EU commission has released an action plan for harmonisation of electronic signatures and electronic identification among European member states.<br />You can download the action plan here </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="../../pub/docs/COM%282008%29798-2008-11-28ActionPlanElectronicSignatures%2BeIdentification.pdf" rel="self">COM (2008) 798final</a></span><span style="font:14px Times, Georgia, Courier, serif; "><br />A presentation on the action plan held at ETSI ESI in Barcelona, March 17 2009 is </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="../../pub/docs/esi23_19_ETSI-ESI%2017032009.pdf" rel="self">here</a></span>]]></content:encoded></item><item><title>Updating the IETF Time Stamp standard</title><dc:creator>stefans@exmsft.com</dc:creator><category>Protocols</category><category>All</category><dc:date>2009-03-14T01:08:22+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/3463eee2a77bdd29d2ad119cf45da090-7.html#unique-entry-id-7</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/3463eee2a77bdd29d2ad119cf45da090-7.html#unique-entry-id-7</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">The IETF standard for time stamps is currently being updated - But are the changes really necessary?</span>]]></content:encoded></item><item><title>PKI Resource Query Protocol (PRQP) Deployed by Federal Bridge and OpenCA</title><dc:creator>stefans@exmsft.com</dc:creator><category>Protocols</category><category>All</category><dc:date>2009-03-11T13:57:40+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/f1929c39136750c5271ad3ca132291bf-6.html#unique-entry-id-6</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/f1929c39136750c5271ad3ca132291bf-6.html#unique-entry-id-6</guid><content:encoded><![CDATA[<span style="font:14px Times, Georgia, Courier, serif; ">A fairly new and unknown protocol, the PKI Resource Query Protocol (PRQP) developed in the IETF </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://www.ietf.org/html.charters/pkix-charter.html" rel="self">PKIX Work Group</a></span><span style="font:14px Times, Georgia, Courier, serif; ">, is being deployed by the US </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://www.cio.gov/fpkisc/" rel="self">Federal Bride</a></span><span style="font:14px Times, Georgia, Courier, serif; "> and </span><span style="font:14px Times, Georgia, Courier, serif; "><a href="http://www.openca.org/" rel="self">OpenCA</a></span><span style="font:14px Times, Georgia, Courier, serif; ">, reports the editor of the current draft, Massimiliano Pala.<br /><br /></span><img class="imageStyle" alt="prqp_simple" src="http://aaa-sec.com/web/blog_files/prqp_simple.png" width="131" height="105"/><span style="font:14px Times, Georgia, Courier, serif; "><br /></span>]]></content:encoded></item><item><title>Events in March - ETSI ESI#23 and IETF 74</title><dc:creator>stefans@exmsft.com</dc:creator><category>Events</category><category>All</category><dc:date>2009-03-10T16:47:55+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/8e9c0197be2bb194bc0ece2c70c9c7cf-5.html#unique-entry-id-5</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/8e9c0197be2bb194bc0ece2c70c9c7cf-5.html#unique-entry-id-5</guid><content:encoded><![CDATA[<img class="imageStyle" alt="Pasted Graphic 2" src="http://aaa-sec.com/web/blog_files/pasted-graphic-3-2.jpg" width="210" height="37"/>  and <img class="imageStyle" alt="Pasted Graphic 1" src="http://aaa-sec.com/web/blog_files/pasted-graphic-4.jpg" width="117" height="64"/> <br /><br />]]></content:encoded></item><item><title>Defining Hash functions without security properties</title><dc:creator>stefans@exmsft.com</dc:creator><category>Protocols</category><category>All</category><dc:date>2009-03-10T03:19:50+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/d08b5a814d8750bd29ddc6d13f4673fb-4.html#unique-entry-id-4</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/d08b5a814d8750bd29ddc6d13f4673fb-4.html#unique-entry-id-4</guid><content:encoded><![CDATA[Do we need hash functions with no security properties in order to not confuse their use with cases when security is a requirement. A current discussion in the International standards community is trying to decide whether to standardise hash functions without security properties.<br /><br /><img class="imageStyle" alt="Pasted Graphic" src="http://aaa-sec.com/web/blog_files/pasted-graphic-3.jpg" width="268" height="65"/>]]></content:encoded></item><item><title>Visual Electronic Identities</title><dc:creator>stefans@exmsft.com</dc:creator><category>Protocols</category><category>Authentication</category><category>Visual eID</category><category>All</category><dc:date>2009-03-09T14:24:13+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/c08104dc5f387730dbd9b94a9d0b7ec5-3.html#unique-entry-id-3</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/c08104dc5f387730dbd9b94a9d0b7ec5-3.html#unique-entry-id-3</guid><content:encoded><![CDATA[How can we provide applications with standard User Interface tools to display a meaningful representation of an electronic identity (eID)<br /> <img class="imageStyle" alt="Pasted Graphic 1" src="http://aaa-sec.com/web/blog_files/pasted-graphic-2.jpg" width="232" height="144"/>]]></content:encoded></item><item><title>Optimising TLS handshake through certificate caching</title><dc:creator>stefans@exmsft.com</dc:creator><category>Protocols</category><category>All</category><dc:date>2009-03-09T11:36:22+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/204130f4e89782f473e5957e56bf39d4-2.html#unique-entry-id-2</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/204130f4e89782f473e5957e56bf39d4-2.html#unique-entry-id-2</guid><content:encoded><![CDATA[A possible but unexplored optimisation of the TLS handshake is to cache server certificates. I&rsquo;m proposing a new IETF standard that specifies a method to accomplish this.]]></content:encoded></item><item><title>All those Passwords</title><dc:creator>stefans@exmsft.com</dc:creator><category>Authentication</category><category>All</category><dc:date>2009-03-08T15:19:19+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/68128694758f9208ffca5cd486d87ce0-1.html#unique-entry-id-1</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/68128694758f9208ffca5cd486d87ce0-1.html#unique-entry-id-1</guid><content:encoded><![CDATA[Passwords are a menace. A discussion I overheard between young students gave me reason to actually feel hopeful.<br /><br /><img class="imageStyle" alt="Pasted Graphic 1" src="http://aaa-sec.com/web/blog_files/pasted-graphic-1.jpg" width="167" height="101"/>]]></content:encoded></item><item><title>Welcome to my blog</title><dc:creator>stefans@exmsft.com</dc:creator><category>All</category><dc:date>2009-03-04T18:34:39+01:00</dc:date><link>http://aaa-sec.com/web/blog_files/6ce7b840e6294c17a354ebca5a12795a-0.html#unique-entry-id-0</link><guid isPermaLink="true">http://aaa-sec.com/web/blog_files/6ce7b840e6294c17a354ebca5a12795a-0.html#unique-entry-id-0</guid><content:encoded><![CDATA[<img class="imageStyle" alt="Pasted Graphic" src="http://aaa-sec.com/web/blog_files/pasted-graphic.jpg" width="177" height="77"/><br />In this Blog I provide information and personal thoughts related to Internet security.<br />I hope you will find some useful thoughts here.<br /><br /><div class="js-kit-comments" permalink=""></div><br />]]></content:encoded></item></channel>
</rss>
