Re: NEA requirements (was Re: Fwd: [Nea] Re: use of a design team to develop requirements)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: NEA requirements (was Re: Fwd: [Nea] Re: use of a design team to develop requirements)



Douglas Otis wrote:
> That was being suggested.  Allow an exchange by reference, and allow
> specific "Host" certificates (those signed with hostmaster@ for example)
> to be requested in order to determine the validity of the service and
> the related resource information based upon mutually trusted
> third-parties.

  That isn't in dispute.

>  You seem to be suggesting that a component of the NEA
> will be creating and vouching for this information.  That would reduce
> the general level of security.

  No, I did NOT say that.  Please read my messages again.

>> Allowing a client to obtain network access if it passes posture
>> assessment by third parties is ridiculous: they don't own the network.
>> The enterprise administrator running the NEA server owns the network,
>> and is the ONLY one who controls network access.
> 
> A mutually trusted service is not ridiculous.

  Did you read the text you're allegedly responding to?

  I won't respond to the rest of your post.  It's yet another repetition
of the same opinions, and doesn't address my earlier comments about
those opinions.

  Alan DeKok.
--
  http://deployingradius.com       - The web site of the book
  http://deployingradius.com/blog/ - The blog

_______________________________________________
Nea mailing list
Nea at ietf.org
https://www1.ietf.org/mailman/listinfo/nea




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.