Re: Machine Identity

Stephane Bortzmeyer <bortzmeyer@nic.fr> Thu, 28 February 2008 16:24 UTC

Return-Path: <discuss-bounces@ietf.org>
X-Original-To: ietfarch-discuss-archive@core3.amsl.com
Delivered-To: ietfarch-discuss-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 3C02528C902; Thu, 28 Feb 2008 08:24:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.173
X-Spam-Level:
X-Spam-Status: No, score=-4.173 tagged_above=-999 required=5 tests=[AWL=2.076, BAYES_00=-2.599, HELO_EQ_FR=0.35, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0HfVF+OrhtXx; Thu, 28 Feb 2008 08:24:14 -0800 (PST)
Received: from core3.amsl.com (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 0EF7F28C8F3; Thu, 28 Feb 2008 08:24:10 -0800 (PST)
X-Original-To: discuss@core3.amsl.com
Delivered-To: discuss@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4957B28C7E4 for <discuss@core3.amsl.com>; Thu, 28 Feb 2008 08:24:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hQKKnSXZTLTp for <discuss@core3.amsl.com>; Thu, 28 Feb 2008 08:24:03 -0800 (PST)
Received: from mx2.nic.fr (mx2.nic.fr [192.134.4.11]) by core3.amsl.com (Postfix) with ESMTP id D963328C908 for <discuss@apps.ietf.org>; Thu, 28 Feb 2008 08:23:11 -0800 (PST)
Received: from mx2.nic.fr (localhost [127.0.0.1]) by mx2.nic.fr (Postfix) with SMTP id AD3EF1C00FF; Thu, 28 Feb 2008 17:23:04 +0100 (CET)
Received: from relay2.nic.fr (relay2.nic.fr [192.134.4.163]) by mx2.nic.fr (Postfix) with ESMTP id A81F81C0167; Thu, 28 Feb 2008 17:23:04 +0100 (CET)
Received: from bortzmeyer.nic.fr (batilda.nic.fr [192.134.4.69]) by relay2.nic.fr (Postfix) with ESMTP id 9B7A858ECCF; Thu, 28 Feb 2008 17:23:04 +0100 (CET)
Date: Thu, 28 Feb 2008 17:23:04 +0100
From: Stephane Bortzmeyer <bortzmeyer@nic.fr>
To: Miika Komu <miika@iki.fi>
Subject: Re: Machine Identity
Message-ID: <20080228162304.GB21463@nic.fr>
References: <20080226130527.GA1404@generic-nic.net> <47C4101B.6050206@spaghetti.zurich.ibm.com> <20080226142754.GA12093@nic.fr> <Pine.SOL.4.64.0802270013060.16365@kekkonen.cs.hut.fi>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <Pine.SOL.4.64.0802270013060.16365@kekkonen.cs.hut.fi>
X-Operating-System: Debian GNU/Linux 4.0
X-Kernel: Linux 2.6.18-6-686 i686
Organization: NIC France
X-URL: http://www.nic.fr/
User-Agent: Mutt/1.5.13 (2006-08-11)
Cc: discuss@apps.ietf.org
X-BeenThere: discuss@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: general discussion of application-layer protocols <discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/discuss>, <mailto:discuss-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:discuss@ietf.org>
List-Help: <mailto:discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/discuss>, <mailto:discuss-request@ietf.org?subject=subscribe>
Sender: discuss-bounces@ietf.org
Errors-To: discuss-bounces@ietf.org

On Wed, Feb 27, 2008 at 12:28:40AM +0200,
 Miika Komu <miika@iki.fi> wrote 
 a message of 39 lines which said:

> While waiting for changes to libc, the DNS interaction can be
> accomplished by running a DNS proxy in the localhost that can do the
> HIP magic.

Hold on, I did not want to actually use the HIP protocol. I was just
thinking aloud about wether it was possible to use Host Identities in
an ordinary application (regardless of wether HIP was running or not).

For instance, suppose we were redesigning SSH from scratch, would it
be possible / would it make sense to use Host Identities instead of
SSH-specific keys?