[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Hipsec] draft-ietf-hip-cert-01



Hi,

This is a resend for the mail concerning the new version of the hip-cert draft. We got only answer to the mail earlier. We would appreciate if people could read the draft and give us comments.

Thans, Samu

Varjonen Samu wrote:
Hi,

http://www.ietf.org/internet-drafts/draft-ietf-hip-cert-01.txt

This new version of the draft brings editorial changes to the group handling and clarifications to the usage of x.509 distinguished name (DN) section.

We would appreciate if people would read the draft and comment it.

We have some additional discussion topics that we would like open. Main point in these questions is to determine the direction where we should take the draft.

- Is the draft sufficient? Do we need to specify something more? Is something important missing?

-Is SPKI the right choice for the default format? X.509 is more widely deployed and has better support vs. SPKI is simpler but has less support.

-Are the hash and URL encodings needed? At least with on-path middleboxes they are problematic.

-Are the examples in the appendixes sufficient?

One discussion topic that is a bit out of scope of hip-cert but is relevant for HIP in general is fragmentation. I have brought this issue up in several of the last meetings. Is there any interest in the group to tackle this issue or should be just left for the IP and its fragmentation to handle?

BR,
Samu
_______________________________________________
Hipsec mailing list
Hipsec at ietf.org
https://www.ietf.org/mailman/listinfo/hipsec