Re: short-lived credential issuance

"RL 'Bob' Morgan" <[email protected]> Thu, 3 Oct 2002 11:42:17 -0700 (PDT)
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>

On Tue, 1 Oct 2002, Lawrence Greenfield wrote:

>    Date: Tue, 1 Oct 2002 09:57:59 -0700 (PDT)
>    From: "RL 'Bob' Morgan" <[email protected]>
> ...
>    Could be.  One could also imagine a SASL-enabled version of one or more of
>    the many standard certficate management protocols.  I don't know enough
>    about any of them to know if one is more suitable for perversion than the
>    others.
>
> Yep. SACRED is tempting since you can imagine a SACRED server that
> either can sign junk certs (for temporary authentication purposes) or
> makes a long term S/MIME cert available for e-mail purposes, and does
> so in the same protocol.

I can imagine a very useful server that both issues certs (as a CA or a
proxy for a CA) and supplies long-term saved credentials, but I don't see
why this requires using the same protocol for both.  As Steven says,
making SACRED compete with CMP/CMC/etc regarding enrollment is likely to
make people upset.  Seems to me the more likely standards approach would
be creating the desired enrollment protocol (the sort of enrollment
protocol that would, for example, provide the functionality that the UMich
KX509/KCA needs), out of one of the existing ones.

A quick glance at specs and drafts regarding CMP and CMC shows that each
is claimed to operate over a variety of "transports" (as stated in
separate I-Ds), and each is capable of being sent via HTTP.  A BEEP
transport for these could presumably work more or less like HTTP but would
provide SASL.  No doubt there are hidden complexities involved in applying
SASL authentication to the cert-management process.

 - RL "Bob"