RE: COPS-TLS extensions

"Kulkarni, Amol" <[email protected]> Tue, 29 Jul 2003 09:16:33 -0700
Newsgroups gmane.ietf.rap
Message-ID <[email protected]>
Hi,

You are correct in your observation that these are the responsibilities
of the application that implements TLS.

What are the extensions you are proposing? Please post them to this
list.

Thanks,
Amol

-----Original Message-----
From: [email protected] [mailto:[email protected]]=20
Sent: Monday, July 28, 2003 8:30 PM
To: [email protected]
Subject: COPS-TLS extensions

Hello
Im am a student studying the use of COPS-PR for distributing=20
firewall security policies over insecure networks. I thus=20
far have a working Java implementation of COPS-PR and COPS-
TLS however some issues have come to my attention regarding=20
TLS session re-use/caching policies for COPS-TLS, as well as=20
policies governing re-handshaking to renew keying material=20
at an appropriate interval.

From my understanding, it is the responsibility of the=20
application that implements TLS to handle these issues, so=20
for my work I am proposing some minor extensions to COPS-TLS=20
that allow greater control over the underlying TLS. Just=20
wandering if anyone has addressed these issues in the past,=20
or if it is a pointless idea.

Many thanks