Re: [TLS] Consensus call for certificate URL extension
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Consensus call for certificate URL extension



I do not know if this extension still has value or not, but as one of the authors of the original RFC 3546, I just wanted to provide some background ...

This extension came about a long time ago when the WAP Forum (today: Open Mobile Alliance) was looking at introducing support for TLS in their architecture. Given bandwidth-constraints in the mobile networks at the time, it made sense to devise a way for clients to not having to send their certificates (or chains) but rather have the servers pick them up somewhere. Clearly, today's networks are more capable.

-- Magnus

On Thu, 25 Sep 2008, Yoav Nir wrote:

On Sep 25, 2008, at 10:24 AM, Simon Josefsson wrote:

If the assumption in (B), that there are no known deployments of this
extension, is correct, my preference is to deprecate the extension,
without creating a new extension with different properties.

The way I am reading the replies so far imply that few if anyone really
needs this extension.  If that is the case, I don't see why we need to
spend time on it.

/Simon

Well, somebody went to the trouble of writing it...

I can see the value of this for a protocol such as IKE, because there you need to send the whole cert (sometimes a chain, sometimes also a CRL) within one UDP packet. With TLS, I guess there is much less value there.


_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls

_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.