[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Hipsec] draft-ietf-hip-cert-02-pre00



Miika Komu wrote:
Samu Varjonen wrote:

Hi,

Mattes, David kirjoitti:
Hi Samu,

As some background, I am focused on using HIP operationally and therefore have a pragmatic point of view of the specifications. Here are some in-line opinions for your questions below.

Also, what is the purpose of requiring the HIT as part of the X.509 information? In practice (at least until HIP is a de-facto standard ;-), I think it will be quite difficult to convince Certificate issuers to include new or different information. I think you should remove that recommendation from the draft.

We do not want to enforce all certificates to have HITs encoded as subjects and/or issuers. It is there if you need to encode HITs. I will rephrase the text to clearly state this.

does the HIT have problems with the planned algo agility mechanism described in here:

http://www.ietf.org/mail-archive/web/hipsec/current/msg02661.html

As I have understood the HIT will remain in the present presentation format and the hash algo is read from DNS or with I1-R1 exchange from the responders HOST-ID. In which, the KEY RR would just have a new algorithm number. This affects the public-key and signature sequences in the certificates but they are defined in their own respective documents (or need to be defined). HIP-cert only describes the parameter, how to carry the certificates in side HIP control messages, and how to encode and use HITs in certificates as entities like issuer and/or subject.

At least, now I do not see any problems, but if something comes up please let me know.

BR,
Samu