IP addresses in certs (Re: DNS and X.501 DistinguishedName)
Harald Tveit Alvestrand <[email protected]> Thu, 11 Jun 1998 09:13:12 +0200
| Newsgroups | gmane.ietf.lsd |
|---|---|
| Message-ID | <[email protected]> |
At 14:43 10.06.98 -0400, Peter Whittaker wrote:
>
>A device's certificate will contain its IP address or hostname in the
>subjectAltName extension, and may contain its DN in the subject field. If
>these certificates are written to and retrieved from the directory, they
will >(likely) be in the entry whose DN is the subject DN in the certificate.
>
Small diatribe:
Please do NOT even consider for more than 60 seconds using the
IP address as an identifier for the host for more than approximately
the same amount of time.
With DHCP, many hosts have IP address lifetimes of hours.
With provider-based addressing, many networks have IP address lifetimes
of months.
With NAT, many hosts have the *same* IP address, so it's not even unique.
The only possible use I can see for an X.509 certificate with an IP address
in it is as part of something like "secure DHCP" - having a certified
assignment of an IP address to a host.
For more info about why IP addresses in applications that don't absolutely
*have* to have them is a Really Bad Thing, see the PIER WG's documents.
Harald A
--
Harald Tveit Alvestrand, Maxware, Norway
[email protected]