Re: short-lived credential issuance
Lawrence Greenfield <[email protected]> Tue, 1 Oct 2002 10:44:37 -0400
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Message-ID | <[email protected]> |
Hi, I've definitely been interested in this. In the higher ed world these short lived certs have frequently been referred to as "junk certs". SACRED is sufficient to make a bootstrapping protocol for junk certs but isn't ideal. An ideal protocol would take some sort of CRL (or simplier format?) from the client and have the server sign it after the client has authenticated. This can be implemented as an extension to the base sacred protocol and is probably not worth cluttering the base document. Larry