[P2PSIP] Multiple node-id in an enrollment certificate

"Michael Chen" <michaelc@idssoftware.com> Sat, 19 October 2013 13:19 UTC

Return-Path: <michaelc@idssoftware.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DFF111E81A9 for <p2psip@ietfa.amsl.com>; Sat, 19 Oct 2013 06:19:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cTuJ+YGb3yyP for <p2psip@ietfa.amsl.com>; Sat, 19 Oct 2013 06:19:35 -0700 (PDT)
Received: from p3plwbeout03-06.prod.phx3.secureserver.net (p3plsmtp03-06-2.prod.phx3.secureserver.net [72.167.218.218]) by ietfa.amsl.com (Postfix) with ESMTP id 3F8C121F9FB0 for <p2psip@ietf.org>; Sat, 19 Oct 2013 06:19:34 -0700 (PDT)
Received: from localhost ([72.167.218.244]) by p3plwbeout03-06.prod.phx3.secureserver.net with bizsmtp id f1KZ1m0015GyNsw011KZyd; Sat, 19 Oct 2013 06:19:33 -0700
X-SID: f1KZ1m0015GyNsw01
Received: (qmail 6085 invoked by uid 99); 19 Oct 2013 13:19:33 -0000
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="=_21c725e1eb61fddc19a59fbb08c67f54"
To: reload-it@implementers.org
From: Michael Chen <michaelc@idssoftware.com>
Date: Sat, 19 Oct 2013 06:19:33 -0700
Message-Id: <20131019061933.59ca11a9ba9389561a029f06442e67fa.92ef585bd6.mailapi@email03.secureserver.net>
X-Originating-IP: 75.85.78.244
User-Agent: MailAPI 24838
X-Sender: michaelc@idssoftware.com
Cc: p2psip@ietf.org
Subject: [P2PSIP] Multiple node-id in an enrollment certificate
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 19 Oct 2013 13:19:41 -0000

Hey Marc,
 
I was wondering about its use case. If you use a multi-node-id certificate on the wire, the receiver wouldn't know which one is being used. You can't make a new cert with one node-id either, because it is signed by the root cert.
 
Thanks
 
--Michael