Re: short-lived credential issuance
"RL 'Bob' Morgan" <[email protected]> Tue, 1 Oct 2002 09:57:59 -0700 (PDT)
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Message-ID | <[email protected]> |
> I've definitely been interested in this. In the higher ed world these > short lived certs have frequently been referred to as "junk certs". One reference to work along this line is: http://www.citi.umich.edu/projects/kerb_pki/ > SACRED is sufficient to make a bootstrapping protocol for junk certs > but isn't ideal. An ideal protocol would take some sort of CRL (or I think you mean CSR. > simplier format?) from the client and have the server sign it after > the client has authenticated. > > This can be implemented as an extension to the base sacred protocol > and is probably not worth cluttering the base document. Could be. One could also imagine a SASL-enabled version of one or more of the many standard certficate management protocols. I don't know enough about any of them to know if one is more suitable for perversion than the others. - RL "Bob"