Re: short-lived credential issuance

Lawrence Greenfield <[email protected]> Tue, 1 Oct 2002 13:42:23 -0400
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>
   Date: Tue, 1 Oct 2002 09:57:59 -0700 (PDT)
   From: "RL 'Bob' Morgan" <[email protected]>
[...]
   > SACRED is sufficient to make a bootstrapping protocol for junk certs
   > but isn't ideal. An ideal protocol would take some sort of CRL (or

   I think you mean CSR.

Yes, of course. Thanks.

   > simplier format?) from the client and have the server sign it after
   > the client has authenticated.
   >
   > This can be implemented as an extension to the base sacred protocol
   > and is probably not worth cluttering the base document.

   Could be.  One could also imagine a SASL-enabled version of one or more of
   the many standard certficate management protocols.  I don't know enough
   about any of them to know if one is more suitable for perversion than the
   others.

Yep. SACRED is tempting since you can imagine a SACRED server that
either can sign junk certs (for temporary authentication purposes) or
makes a long term S/MIME cert available for e-mail purposes, and does
so in the same protocol.

Larry