Re: short-lived credential issuance

Stephen Farrell <[email protected]> Tue, 01 Oct 2002 14:27:44 +0100
Newsgroups gmane.ietf.sacred
Organization Baltimore Technologies Ltd.
Message-ID <[email protected]>

Hi Trevor,

One of the decisions that we made early on was that the SACRED credential 
server can treat the credential data as an opaque blob (as far as the 
protocol is concerned, your own implementation might do more than that,
of course).

Another decision we made was to introduce a hint in the download 
response as to the duration for which this downloaded credential ought
to be used at the client. (Just a hint, since the server can't enforce
anything).

Putting those two together would I think mean that SACRED is usable
as-is for short-lived/transient credentials.

In order to get the best behaviour you might want to define something
other than pkcs1#15 as the default credential format, and/or write a 
separate I-D that adds a MUST honor the download response TTL for clients, 
but other than that I can't see anything missing. (Though that's no 
guarantee - you need to check for yourself:-)

Cheers,
Stephen.


Trevor Perrin wrote:
> 
> Greeting SACRED,
> 
> A question about a possible use case:
> 
> It seems that SACRED could be used for issuing short-lived credentials
> (certs+keypairs).  To client software, there wouldn't be much difference
> between retrieving a static, long-lived credential or getting a transient,
> freshly-issued one.
> 
> Short-lived credentials are useful because they expire quickly so don't need
> to be revoked, and don't need to be stored on the server (the server might
> be stateless, and simply refer all authentications to a legacy auth server
> like RADIUS).
> 
> SACRED isn't ideal for cert issuance.  A protocol designed for it, like
> IPsec's PIC, can deal in certificate requests and thus allow the client to
> keep secret his private key, and have input into the certificate contents.
> But having a single, general protocol for client apps to retrieve either
> static or transient credentials might cause people to use SACRED for this
> anyways.
> 
> So should the SACRED protocol take this into account?  I'm not sure how,
> maybe no changes are needed.  Maybe there could be a well-known selector
> named "transient", for example.
> 
> I'm just curious if this is worth thinking about further, or if it's out of
> scope.
> 
> Trevor

-- 
____________________________________________________________
Stephen Farrell         				   
Baltimore Technologies,   tel: (direct line) +353 1 881 6716
39 Parkgate Street,                     fax: +353 1 881 7000
Dublin 8.                mailto:[email protected]
Ireland                             http://www.baltimore.com