Re: On the need for presence service identifiers

[email protected] (John D. Ramsdell)
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
This exchange on presence service identifiers should be taken as a
warning on the dangers of considering notification authentication
without thinking about subscription authentication.  Had I focused
only on notification authentication, my argument for a presence
service identifier would have centered around the fact that a lack of
one implies that a signing presence service would be required to
maintain a private key for each user of its service.  Obviously, a
design that requires this is bogus.  Can you imagine AOL's AIM servers
maintaining that many private keys?

The case becomes even stronger, however, when one considers
subscription authentication.  In this case, duplicate, but matching
certificates and their private keys must be maintain in different
locations.  Only when one considers subscription authentication does
the logistics nightmare become evident.

John

[email protected] (John D. Ramsdell) writes:

> "Adrian Bateman" <[email protected]> writes:
> 
> > Why does there need to be two certificates? If the presence service is
> > doing the signing, only it needs the certificate.
> 
> Yes, your right.  I was thinking ahead to the case in which
> subscription requests are signed.  In that case, for each user, there
> is a certificate for the user, and one for the presence server.
> Thanks for point that out.
> 
> John



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.