Re: issue-#48: Use of trusted-anchor sub-option between Access Routers
"James Kempf" <[email protected]> Tue, 11 May 2004 10:16:35 -0700
| Newsgroups | gmane.ietf.seamoby |
|---|---|
| Message-ID | <[email protected]> |
Marco,
>
> Another point: Is the Trusted Anchor always to be sent from a mobile to
> it current AR in case of
> certificates are requested? If the current AR and a CAR share the same
> CA, the chain from the mobile's
> trusted CA to the ARs' CA should have been validated already in a
> previous request.
The Trusted Anchor only needs to be sent once, and only if the certificates
are required. If the mobile node has the certificate chain, either through
preconfiguration or through having received it through a previous router,
then the Trusted Anchor doesn't need to be sent. But the Trusted Anchor does
need to be sent if certs are required, otherwise the router won't know what
chain to reply with.
Can you suggest a place in the text where this should be made clearer?
> Hence, subsequent cert requests do not necessarily require a Trusted
> Anchor to be sent
> with the MN-AR CARD Request, right?
> Here, the flag could serve for the same purpose in the MN-AR CARD Request.
>
The cert request doesn't ever have to be done except once (and not even then
if the mobile node has the certs through some other means).
As for using the flag, I doubt the mobile node would really want to get all
the certs. Of course, access router certs are not yet deployed, so it is
difficult at this time to know exactly how many cert chains will be
necessary, but if this develops anything like the certs used for browser
traffic, then there could be hundreds of certs required on the router. I
don't think we want to encourage the mobile node to download all the cert
chains (if there are more than one), when it really only needs one.
> Furthermore, do we have to distinguish between a requested certificate
> of a CAR or
> a requested cert of a mobile's current AR?
Yes. The mobile uses the cert chain for the current AR to perform validation
of CARD messages on the current AR, it uses the cert chain for CARs to
perform CARD on other ARs.
> Well, I think the current
> mechanism
> uses the L2-ID for that. If the L2-ID belongs to an Access Point
> associated with the
> current AR, the cert of the current AR will be sent back, otherwise the
> cert of the CAR will
> be sent in the reply. Shouldn't we de-couple a cert request from the L2-ID
> sub-option?
>
> What do you think?
>
I think we need to distinguish. It is possible that an WISP would use one
set of certs for one part of the access network and another for another
part. If the mobile is in transition between the two, it must be able to
distinguish which certs belong to which routers. The L2-ID distinguishes,
and is included in the cert request in order to identify which AR is
designated.
jak