Re: short-lived credential issuance

"RL 'Bob' Morgan" <[email protected]> Tue, 1 Oct 2002 09:57:59 -0700 (PDT)
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>

> I've definitely been interested in this. In the higher ed world these
> short lived certs have frequently been referred to as "junk certs".

One reference to work along this line is:

  http://www.citi.umich.edu/projects/kerb_pki/

> SACRED is sufficient to make a bootstrapping protocol for junk certs
> but isn't ideal. An ideal protocol would take some sort of CRL (or

I think you mean CSR.

> simplier format?) from the client and have the server sign it after
> the client has authenticated.
>
> This can be implemented as an extension to the base sacred protocol
> and is probably not worth cluttering the base document.

Could be.  One could also imagine a SASL-enabled version of one or more of
the many standard certficate management protocols.  I don't know enough
about any of them to know if one is more suitable for perversion than the
others.

 - RL "Bob"