Re: [kitten] Is id-pkinit-san misnamed? Can it be reused by kca?
Jeffrey Altman <jaltman@secure-endpoints.com> Fri, 06 December 2013 00:50 UTC
Return-Path: <prvs=1052909841=jaltman@secure-endpoints.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0D9361AE236 for <kitten@ietfa.amsl.com>; Thu, 5 Dec 2013 16:50:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A1E2B4k9W9CP for <kitten@ietfa.amsl.com>; Thu, 5 Dec 2013 16:50:30 -0800 (PST)
Received: from mail.secure-endpoints.com (sequoia-grove.ad.secure-endpoints.com [208.125.0.235]) by ietfa.amsl.com (Postfix) with ESMTP id 2595A1AE23F for <kitten@ietf.org>; Thu, 5 Dec 2013 16:50:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=secure-endpoints.com; s=MDaemon; t=1386291026; x=1386895826; q=dns/txt; h=DomainKey-Signature:Received:VBR-Info:Message-ID: Date:From:Organization:User-Agent:MIME-Version:To:CC:Subject: References:In-Reply-To:OpenPGP:Content-Type; bh=PDkC8U1/hI2oHKQ5 h1OhvjOhDsSL/vJ16zzNRLFfJp8=; b=fKVrkgoDXTYPQRcyw8GOF5gdvdeBeklT F40rFL+kqRcidHaOvkywChTJOdG5JrwNKdUK0rozhKcY1eXwYglDBVLeEa/NFtZJ qxCKJFHrBCg04A7N7hJyQ6oWXh1EZrPYsndmroaIOp6DmJYY5sOjR3NpY/VQHt8h D8Nw2ue1FCo=
DomainKey-Signature: a=rsa-sha1; s=MDaemon; d=secure-endpoints.com; c=simple; q=dns; h=message-id:from; b=qcnT/jbKam964RcvFPqD/OAKum1WWV++mM36+zltcH1BJR6jz87rE4/1XwrF YpqYWS/3siD3z+c3on+tgHWkFyDC35JmyFjn7yULJRr7wAqh31da/PWTX 0fwHW6o9kKpqhS56axZhdSzg6alKrC+8DAaQOIGU9T/4j/7ZtvDHy4=;
X-MDAV-Result: clean
X-MDAV-Processed: mail.secure-endpoints.com, Thu, 05 Dec 2013 19:50:26 -0500
Received: from [172.16.16.54] by secure-endpoints.com (Cipher TLSv1:AES-SHA:128) (MDaemon PRO v13.6.0) with ESMTP id md50000555604.msg for <kitten@ietf.org>; Thu, 05 Dec 2013 19:50:25 -0500
VBR-Info: md=secure-endpoints.com; mc=all; mv=vbr.emailcertification.org;
X-Spam-Processed: mail.secure-endpoints.com, Thu, 05 Dec 2013 19:50:25 -0500 (not processed: message from trusted or authenticated source)
X-Authenticated-Sender: jaltman@secure-endpoints.com
X-HashCash: 1:22:131206:md50000555604::zJHM61cPi5jYA1w3:0000UtpZ
X-Return-Path: prvs=1052909841=jaltman@secure-endpoints.com
X-Envelope-From: jaltman@secure-endpoints.com
X-MDaemon-Deliver-To: kitten@ietf.org
Message-ID: <52A11F4C.90605@secure-endpoints.com>
Date: Thu, 05 Dec 2013 19:50:20 -0500
From: Jeffrey Altman <jaltman@secure-endpoints.com>
Organization: Secure Endpoints Inc.
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.1.1
MIME-Version: 1.0
To: Jeffrey Hutzelman <jhutz@cmu.edu>, Nico Williams <nico@cryptonector.com>
References: <24661_1386227942_rB57J0KZ025231_20131205071852.GO21240@localhost> <1386276313.9407.139.camel@minbar.fac.cs.cmu.edu>
In-Reply-To: <1386276313.9407.139.camel@minbar.fac.cs.cmu.edu>
X-Enigmail-Version: 1.6
OpenPGP: url=http://pgp.mit.edu
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha1"; boundary="------------ms090705060207010007030606"
Cc: kitten@ietf.org
Subject: Re: [kitten] Is id-pkinit-san misnamed? Can it be reused by kca?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 Dec 2013 00:50:32 -0000
On 12/5/2013 3:45 PM, Jeffrey Hutzelman wrote: > On Thu, 2013-12-05 at 01:18 -0600, Nico Williams wrote: >> PKINIT (RFC4556) adds a PKIX certicate SAN (id-pkinit-san) for representing Kerberos >> principal names of AS clients and servers. >> >> I believe that id-pkinit-san does not denote "for PKINIT", and therefore >> was misnamed. It should have been named id-kerberos-san. > > Indeed. This was always intended to be the way to represent Kerberos > principal names in certs; PKINIT was just the first thing to get there. > > -- Jeff Just for the record, the UMich kx509 KCA service uses /* * krb5PrincipalName, as defined in RFC 1510 and pkinit draft * * Realm ::= GeneralString * * PrincipalName ::= SEQUENCE { * name-type[0] INTEGER, * name-string[1] SEQUENCE OF GeneralString * } * * KerberosName ::= SEQUENCE { * realm [0] Realm, -- as define in RFC 1510 * principalName [1] PrincipalName, -- as define in RFC 1510 * } * * krb5 OBJECT IDENTIFIER ::= { * iso (1) org (3) dod (6) internet (1) security (5) kerberosv5 (2) * } * * krb5PrincipalName OBJECT IDENTIFIER ::= { krb5 2 } * */ This was taken from draft-ietf-cat-kerberos-pk-init-09. It was removed in draft-ietf-cat-kerberos-pk-init-17. Jeffrey Altman
- [kitten] Is id-pkinit-san misnamed? Can it be reu… Nico Williams
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Nico Williams
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Luke Howard
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Jeffrey Hutzelman
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Nico Williams
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Nico Williams
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Jeffrey Hutzelman
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Nico Williams
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Nico Williams
- Re: [kitten] Is id-pkinit-san misnamed? Can it be… Jeffrey Altman