Re: [hiprg] draft-zhang-hip-hierarchical-parameter-00:Includinghieararchy in HIT generation

Tobias Heer <heer@cs.rwth-aachen.de> Mon, 10 August 2009 18:16 UTC

Return-Path: <heer@informatik.rwth-aachen.de>
X-Original-To: hiprg@core3.amsl.com
Delivered-To: hiprg@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 3FB3D3A6EA8 for <hiprg@core3.amsl.com>; Mon, 10 Aug 2009 11:16:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.801
X-Spam-Level:
X-Spam-Status: No, score=-4.801 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gtoaaEvvz2y8 for <hiprg@core3.amsl.com>; Mon, 10 Aug 2009 11:16:36 -0700 (PDT)
Received: from mta-1.ms.rz.rwth-aachen.de (mta-1.ms.rz.RWTH-Aachen.DE [134.130.7.72]) by core3.amsl.com (Postfix) with ESMTP id 2EEB63A6C53 for <hiprg@irtf.org>; Mon, 10 Aug 2009 11:16:36 -0700 (PDT)
MIME-version: 1.0
Content-transfer-encoding: 7bit
Content-type: text/plain; charset="US-ASCII"; format="flowed"; delsp="yes"
Received: from ironport-out-1.rz.rwth-aachen.de ([134.130.5.40]) by mta-1.ms.rz.RWTH-Aachen.de (Sun Java(tm) System Messaging Server 6.3-7.04 (built Sep 26 2008)) with ESMTP id <0KO600G2RARQYR00@mta-1.ms.rz.RWTH-Aachen.de> for hiprg@irtf.org; Mon, 10 Aug 2009 20:16:38 +0200 (CEST)
X-IronPort-AV: E=Sophos;i="4.43,354,1246831200"; d="scan'208";a="22056566"
Received: from relay-auth-1.ms.rz.rwth-aachen.de (HELO relay-auth-1) ([134.130.7.78]) by ironport-in-1.rz.rwth-aachen.de with ESMTP; Mon, 10 Aug 2009 20:16:39 +0200
Received: from [192.168.178.21] ([unknown] [62.78.196.88]) by relay-auth-1.ms.rz.rwth-aachen.de (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 9 2008)) with ESMTPA id <0KO600IYCARQ9N30@relay-auth-1.ms.rz.rwth-aachen.de> for hiprg@irtf.org; Mon, 10 Aug 2009 20:16:38 +0200 (CEST)
Message-id: <1BD110F3-FDE7-48BA-9E42-61B1D6B400E0@cs.rwth-aachen.de>
From: Tobias Heer <heer@cs.rwth-aachen.de>
To: "Henderson, Thomas R" <thomas.r.henderson@boeing.com>
In-reply-to: <77F357662F8BFA4CA7074B0410171B6D0A8B7220@XCH-NW-5V1.nw.nos.boeing.com>
Date: Mon, 10 Aug 2009 21:16:35 +0300
References: <C1CCBFC6-D133-4CCE-8ABF-3B7A88EC9B0B@cs.rwth-aachen.de> <77F357662F8BFA4CA7074B0410171B6D0A8B7219@XCH-NW-5V1.nw.nos.boeing.com> <A49729CD-84AF-49AF-93CE-2B5210E0C21D@cs.rwth-aachen.de> <77F357662F8BFA4CA7074B0410171B6D0A8B7220@XCH-NW-5V1.nw.nos.boeing.com>
X-Mailer: Apple Mail (2.935.3)
Cc: hiprg@irtf.org
Subject: Re: [hiprg] draft-zhang-hip-hierarchical-parameter-00:Includinghieararchy in HIT generation
X-BeenThere: hiprg@irtf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "Host Identity Protocol \(HIP\) Research Group" <hiprg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/listinfo/hiprg>, <mailto:hiprg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/hiprg>
List-Post: <mailto:hiprg@irtf.org>
List-Help: <mailto:hiprg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/hiprg>, <mailto:hiprg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Aug 2009 18:16:37 -0000

Am 10.08.2009 um 20:33 schrieb Henderson, Thomas R:

>> Hence, the
>> hierarchy information would be self certifying in the sense
>> that if I
>> give a HIT to someone, the hierarchy would be bound to it and
>> it would
>> stay like that unless I changed my HIT.
>
> ...
>
>> The proposed solution was not meant to replace the hierarchy
>> information in an additional parameter it was only intended
>> to have a
>> stronger binding between hierarchy information and HIT.
>
> Maybe this is a terminology issue but I don't think of this as a  
> binding
> or as self-certifying, in the same way that a certificate binds a name
> to a principal, or in the way that current HITs are self-certifying,
> because there is no authorization to use the hierarchy bits.
>
> - Tom

I agree, this is probably a terminology problem. I also agree that  
this binding (or call it linking if you prefer) does not imply  
authorized use of the hierarchy data in the HIT generation.

BR, Tobias


--  

Dipl.-Inform. Tobias Heer, Ph.D. Student
Distributed Systems Group
RWTH Aachen University, Germany
tel: +49 241 80 207 76
web: http://ds.cs.rwth-aachen.de/members/heer