Re: short-lived credential issuance
Stephen Farrell <[email protected]> Tue, 01 Oct 2002 14:27:44 +0100
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Baltimore Technologies Ltd. |
| Message-ID | <[email protected]> |
Hi Trevor, One of the decisions that we made early on was that the SACRED credential server can treat the credential data as an opaque blob (as far as the protocol is concerned, your own implementation might do more than that, of course). Another decision we made was to introduce a hint in the download response as to the duration for which this downloaded credential ought to be used at the client. (Just a hint, since the server can't enforce anything). Putting those two together would I think mean that SACRED is usable as-is for short-lived/transient credentials. In order to get the best behaviour you might want to define something other than pkcs1#15 as the default credential format, and/or write a separate I-D that adds a MUST honor the download response TTL for clients, but other than that I can't see anything missing. (Though that's no guarantee - you need to check for yourself:-) Cheers, Stephen. Trevor Perrin wrote: > > Greeting SACRED, > > A question about a possible use case: > > It seems that SACRED could be used for issuing short-lived credentials > (certs+keypairs). To client software, there wouldn't be much difference > between retrieving a static, long-lived credential or getting a transient, > freshly-issued one. > > Short-lived credentials are useful because they expire quickly so don't need > to be revoked, and don't need to be stored on the server (the server might > be stateless, and simply refer all authentications to a legacy auth server > like RADIUS). > > SACRED isn't ideal for cert issuance. A protocol designed for it, like > IPsec's PIC, can deal in certificate requests and thus allow the client to > keep secret his private key, and have input into the certificate contents. > But having a single, general protocol for client apps to retrieve either > static or transient credentials might cause people to use SACRED for this > anyways. > > So should the SACRED protocol take this into account? I'm not sure how, > maybe no changes are needed. Maybe there could be a well-known selector > named "transient", for example. > > I'm just curious if this is worth thinking about further, or if it's out of > scope. > > Trevor -- ____________________________________________________________ Stephen Farrell Baltimore Technologies, tel: (direct line) +353 1 881 6716 39 Parkgate Street, fax: +353 1 881 7000 Dublin 8. mailto:[email protected] Ireland http://www.baltimore.com