Re: issue-#48: Use of trusted-anchor sub-option between Access Routers
Marco Liebsch <[email protected]> Tue, 11 May 2004 18:32:35 +0200
| Newsgroups | gmane.ietf.seamoby |
|---|---|
| Message-ID | <[email protected]> |
Another point: Is the Trusted Anchor always to be sent from a mobile to it current AR in case of certificates are requested? If the current AR and a CAR share the same CA, the chain from the mobile's trusted CA to the ARs' CA should have been validated already in a previous request. Hence, subsequent cert requests do not necessarily require a Trusted Anchor to be sent with the MN-AR CARD Request, right? Here, the flag could serve for the same purpose in the MN-AR CARD Request. Furthermore, do we have to distinguish between a requested certificate of a CAR or a requested cert of a mobile's current AR? Well, I think the current mechanism uses the L2-ID for that. If the L2-ID belongs to an Access Point associated with the current AR, the cert of the current AR will be sent back, otherwise the cert of the CAR will be sent in the reply. Shouldn't we de-couple a cert request from the L2-ID sub-option? What do you think? marco James Kempf wrote: >The issue is that draft 07 requires use of the Trusted Anchor sub-option >between access routers for an AR to request its CAR to send certificates. >Typically an AR would be interested in obtaining certificate chains for all >trusted anchors possessed by the CAR, and since there is no logical >bandwidth limitation on the inter-router interface, there is no reason to >limit the number of certificates transmitted. > >The suggested resolution is to include a flag in the CARD Request header for >the AR to indicate that it wants all the certificate chains. > > jak > > > >_______________________________________________ >Seamoby mailing list >[email protected] >https://www1.ietf.org/mailman/listinfo/seamoby > >