Re: short-lived credential issuance

Lawrence Greenfield <[email protected]> Tue, 1 Oct 2002 10:44:37 -0400
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>
Hi,

I've definitely been interested in this. In the higher ed world these
short lived certs have frequently been referred to as "junk certs".

SACRED is sufficient to make a bootstrapping protocol for junk certs
but isn't ideal. An ideal protocol would take some sort of CRL (or
simplier format?) from the client and have the server sign it after
the client has authenticated.

This can be implemented as an extension to the base sacred protocol
and is probably not worth cluttering the base document.

Larry