From sacadmin Thu Apr 20 20:34:18 2006
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9) with ESMTP id k3L3YIIQ008468;
	Thu, 20 Apr 2006 20:34:18 -0700 (PDT)
Received: (from kais@localhost)
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9/Submit) id k3L3YIEV008464;
	Thu, 20 Apr 2006 20:34:18 -0700 (PDT)
Date: Thu, 20 Apr 2006 20:34:18 -0700 (PDT)
From: Kais Belgaied <kais@sac.sfbay.sun.com>
Message-Id: <200604210334.k3L3YIEV008464@sac.sfbay.sun.com>
To: PSARC@sac.sfbay.sun.com
Cc: ef-core@sun.com, gh-core@sun.com
Subject: Certificate chain support in kernel SSL [PSARC/2006/263 Timeout:  04/27/2006]
Status: RO
Content-Length: 2314

Subject: PSARC FastTrack [04/27/2006]: Certificate chain support in kernel SSL


Template Version: @(#)sac_nextcase 1.56 10/26/05 SMI
1. Introduction
    1.1. Project/Component Working Name:
	 Certificate chain support in kernel SSL
    1.2. Name of Document Author/Supplier:
	 Author:  Krishna Yenduri
    1.3  Date of This Document:
	20 April, 2006
4. Technical Description

Title: Certificate chain support in kernel SSL

The interface taxonomy is Evolving.
Release binding is micro/patch. The man
page diffs are in the case directory.

Problem:
--------
The kernel SSL project (PSARC 2002/557 and PSARC 2005/625)
introduced an administrative command, ksslcfg(1M). This
command currently does not support certificate chain
for the server certificate.

We need this functionality as there is a customer
escalation for it (See 5106865 cert chain support is needed in kernel SSL).


Solution:
---------
The following changes are proposed to ksslcfg (1M).

1. The file, key_and_certificate_file, in
	ksslcfg create -f pem -i <key_and_certificate_file> ...
	and
	ksslcfg create -f pkcs12 -i <key_and_certificate_file> ...
	
can now take intermediate CA certificates which form the
certificate chain to the root CA for the server certificate.

The order must be the order that is followed in Apache ssl.conf
i.e.
 <server_cert> <middle_level_ca_cert> <next_level_ca_cert>...

2. A new option [-h <ca_certchain_file>] is added
for ksslcfg create -f pkcs11.

A new option is needed as there is no API to build a certificate
chain given a certificate in a PKCS#11 key store. An RFE is filed
 6407962 need a routine to get certificate chain given a
         certificate in a PKCS #11 key store

We need an immediate solution though to address the customer need.
Hence the new option is proposed instead of waiting for
RFE 6407962 to be done as part of KMF project.

The file, ca_certchain_file, is in PEM format. We chose
PEM format because it is a format used by the
Sun Java System web server to import certificates in to
its PKCS#11 key store. It is also the default certificate format
for the Apache webserver.

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack

From sacadmin Thu Apr 27 19:19:07 2006
Received: from localhost.east.sun.com (punchin-sommerfeld.East.Sun.COM [129.148.19.3])
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9) with ESMTP id k3S2J6IQ009526;
	Thu, 27 Apr 2006 19:19:06 -0700 (PDT)
Received: from localhost.east.sun.com (localhost [127.0.0.1])
	by localhost.east.sun.com (8.13.5+Sun/8.13.5) with ESMTP id k3S2HVQK007840;
	Fri, 28 Apr 2006 02:17:31 GMT
Received: (from sommerfeld@localhost)
	by localhost.east.sun.com (8.13.5+Sun/8.13.5/Submit) id k3S2HVfI007839;
	Thu, 27 Apr 2006 22:17:31 -0400 (EDT)
X-Authentication-Warning: localhost.east.sun.com: sommerfeld set sender to sommerfeld@sun.com using -f
Subject: Re: Certificate chain support in kernel SSL [PSARC/2006/263
	Timeout: 04/27/2006]
From: Bill Sommerfeld <sommerfeld@sun.com>
To: Kais Belgaied <kais@sac.sfbay.sun.com>
Cc: PSARC@sac.sfbay.sun.com, ef-core@sun.com, gh-core@sun.com
In-Reply-To: <200604210334.k3L3YIEV008464@sac.sfbay.sun.com>
References: <200604210334.k3L3YIEV008464@sac.sfbay.sun.com>
Content-Type: text/plain; charset=ASCII
Content-Transfer-Encoding: 7bit
Message-Id: <1146190650.7823.4.camel@localhost>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.334 
Date: Thu, 27 Apr 2006 22:17:31 -0400
Status: RO
Content-Length: 148

During Wednesday's PSARC meeting I asked to let this case run so I could
take a look at it.  

I've reviewed it and am happy with it as proposed.



From sacadmin Fri Apr 28 09:48:56 2006
Received: from jurassic.eng.sun.com (jurassic.SFBay.Sun.COM [129.146.226.31])
	by sac.sfbay.sun.com (8.12.9+Sun/8.12.9) with ESMTP id k3SGmtIQ022789;
	Fri, 28 Apr 2006 09:48:55 -0700 (PDT)
Received: from [129.146.11.214] (sr1-umpk-22.SFBay.Sun.COM [129.146.11.214])
	by jurassic.eng.sun.com (8.13.6+Sun/8.13.6) with ESMTP id k3SGmtLZ111265;
	Fri, 28 Apr 2006 09:48:55 -0700 (PDT)
Message-ID: <4452475D.7030002@Sun.COM>
Date: Fri, 28 Apr 2006 09:48:29 -0700
From: Kais Belgaied <Kais.Belgaied@Sun.COM>
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.7) Gecko/20050530
X-Accept-Language: ar-eg, en-us, en, ar, ar-dz, ar-bh, ar-iq, ar-jo, ar-kw, ar-lb, ar-ly, ar-ma, ar-om, ar-qa, ar-sa, ar-sy, ar-tn, ar-ae, ar-ye
MIME-Version: 1.0
To: Bill Sommerfeld <sommerfeld@Sun.COM>
CC: Kais Belgaied <kais@sac.sfbay.sun.com>, PSARC@sac.sfbay.sun.com,
   ef-core@Sun.COM, gh-core@Sun.COM
Subject: Re: Certificate chain support in kernel SSL [PSARC/2006/263	Timeout:
 04/27/2006]
References: <200604210334.k3L3YIEV008464@sac.sfbay.sun.com> <1146190650.7823.4.camel@localhost>
In-Reply-To: <1146190650.7823.4.camel@localhost>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Status: RO
Content-Length: 271



Bill Sommerfeld wrote On 04/27/06 19:17,:

>During Wednesday's PSARC meeting I asked to let this case run so I could
>take a look at it.  
>
>I've reviewed it and am happy with it as proposed.
>  
>

thanks.

The cases in now marked closed approved.

    Kais

>
>  
>

