Re: issue-#48: Use of trusted-anchor sub-option between Access Routers

Marco Liebsch <[email protected]> Tue, 11 May 2004 18:32:35 +0200
Newsgroups gmane.ietf.seamoby
Message-ID <[email protected]>
Another point: Is the Trusted Anchor always to be sent from a mobile to 
it current AR in case of
certificates are requested? If the current AR and a CAR share the same 
CA, the chain from the mobile's
trusted CA to the ARs' CA should have been validated already in a 
previous request.
Hence, subsequent cert requests do not necessarily require a Trusted 
Anchor to be sent
with the MN-AR CARD Request, right?
Here, the flag could serve for the same purpose in the MN-AR CARD Request.

Furthermore, do we have to distinguish between a requested certificate 
of a CAR or
a requested cert of a mobile's current AR? Well, I think the current 
mechanism
uses the L2-ID for that. If the L2-ID belongs to an Access Point 
associated with the
current AR, the cert of the current AR will be sent back, otherwise the 
cert of the CAR will
be sent in the reply. Shouldn't we de-couple a cert request from the L2-ID
sub-option?

What do you think?

marco

James Kempf wrote:

>The issue is that draft 07 requires use of the Trusted Anchor sub-option
>between access routers for an AR to request its CAR to send certificates.
>Typically an AR would be interested in obtaining certificate chains for all
>trusted anchors possessed by the CAR, and since there is no logical
>bandwidth limitation on the inter-router interface, there is no reason to
>limit the number of certificates transmitted.
>
>The suggested resolution is to include a flag in the CARD Request header for
>the AR to indicate that it wants all the certificate chains.
>
>            jak
>
>
>
>_______________________________________________
>Seamoby mailing list
>[email protected]
>https://www1.ietf.org/mailman/listinfo/seamoby
>  
>