Re: [Emu] Idea: New X509 Extension for securing EAP-TLS

Jan-Frederik Rieckers <rieckers@uni-bremen.de> Wed, 13 November 2019 14:32 UTC

Return-Path: <rieckers@uni-bremen.de>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 187051200D7 for <emu@ietfa.amsl.com>; Wed, 13 Nov 2019 06:32:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.401
X-Spam-Level:
X-Spam-Status: No, score=-2.401 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=uni-bremen.de
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0FJe3xV8kJKa for <emu@ietfa.amsl.com>; Wed, 13 Nov 2019 06:32:11 -0800 (PST)
Received: from gabriel-vm-2.zfn.uni-bremen.de (gabriel-vm-2.zfn.uni-bremen.de [134.102.50.17]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3E5EE12003E for <emu@ietf.org>; Wed, 13 Nov 2019 06:32:10 -0800 (PST)
Received: from [10.11.85.85] (vpn-client.noc.uni-bremen.de [134.102.5.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by gabriel-vm-2.zfn.uni-bremen.de (Postfix) with ESMTPSA id 47CnBK0bg9zyP1 for <emu@ietf.org>; Wed, 13 Nov 2019 15:32:09 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=uni-bremen.de; s=2019; t=1573655529; bh=OWX9VKS+BB3XQ/We+RbsqdAGqbvw8qWOp61EFvM/49A=; h=To:References:From:Date:In-Reply-To; b=VkKE2sPgmqTiMeKGcFm+pmJsGb0WHuk895qn8CnqFOcGXV/W//IoXrxzzSvUB6QuY QqDGWpz2cAFhpLewxOoYN8IwRZdu6+1+d15XibfE1kfGtPWV1HvXEpXntAuXg3HU0Y Kqbz5ulgbWJj2BVqUT5uYa29ooSZKwQCX9MMZ6iBjn3DaClRHI31lIywiyL/a3LHQu vL13sgDWiysDEW8BkFZpJlXTC4uDqzn8nclq10WFlPW/o2uyLnE/gbP+dOtF3mTvlL DJJ1j/er7CeOD/q3EH0afLk59oZMYwIgUdrlKSwZgokew45vd4HP5MB4STOHCbPyoo VyI2fLHFcSdAQ==
To: emu@ietf.org
References: <102dd850-b1ae-3426-8189-45876b7b419d@uni-bremen.de>
From: Jan-Frederik Rieckers <rieckers@uni-bremen.de>
Openpgp: preference=signencrypt
Message-ID: <049d789f-08af-dc75-37f9-c977e1e1c5a9@uni-bremen.de>
Date: Wed, 13 Nov 2019 15:32:05 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.8.0
MIME-Version: 1.0
In-Reply-To: <102dd850-b1ae-3426-8189-45876b7b419d@uni-bremen.de>
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="kOlQV8UANZLPf2dz5PkvToMeJOQrTxjHI"
Archived-At: <https://mailarchive.ietf.org/arch/msg/emu/vv-i1bJe6LUT1HdxzcmUIc7lR7c>
Subject: Re: [Emu] Idea: New X509 Extension for securing EAP-TLS
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Nov 2019 14:32:13 -0000

There has been some discussion about this idea. I don't have any
experience in IETF work yet, so I don't know how this discussion can go on.
I would be happy to present my deployment experiences from eduroam and
the basic idea in Singapore. (Since I won't attend the meeting in
person, I would join from remote)
Is there room for that?

 Jan-Frederik Rieckers