RE: request for WG to adopt draft-chadwick-webdav-00.txt as a work item

Stefan Santesson <stefans@microsoft.com> Thu, 06 September 2007 11:38 UTC

Return-path: <owner-ietf-pkix@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1ITFhC-0004hk-Bp for pkix-archive@lists.ietf.org; Thu, 06 Sep 2007 07:38:50 -0400
Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1ITFhA-0003pt-Qz for pkix-archive@lists.ietf.org; Thu, 06 Sep 2007 07:38:50 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l86ACOj0021039 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 6 Sep 2007 03:12:24 -0700 (MST) (envelope-from owner-ietf-pkix@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l86ACOaf021038; Thu, 6 Sep 2007 03:12:24 -0700 (MST) (envelope-from owner-ietf-pkix@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-pkix@mail.imc.org using -f
Received: from smtp-dub.microsoft.com (smtp-dub.microsoft.com [213.199.138.181]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l86ACH8N021009 (version=TLSv1/SSLv3 cipher=RC4-MD5 bits=128 verify=NO) for <ietf-pkix@imc.org>; Thu, 6 Sep 2007 03:12:23 -0700 (MST) (envelope-from stefans@microsoft.com)
Received: from DUB-EXHUB-C301.europe.corp.microsoft.com (65.53.213.91) by DUB-EXGWY-E802.partners.extranet.microsoft.com (10.251.129.2) with Microsoft SMTP Server (TLS) id 8.1.177.2; Thu, 6 Sep 2007 11:12:16 +0100
Received: from EA-EXMSG-C307.europe.corp.microsoft.com ([65.53.221.50]) by DUB-EXHUB-C301.europe.corp.microsoft.com ([65.53.213.91]) with mapi; Thu, 6 Sep 2007 11:12:15 +0100
From: Stefan Santesson <stefans@microsoft.com>
To: George Michaelson <ggm@apnic.net>, "ietf-pkix@imc.org" <ietf-pkix@imc.org>
Date: Thu, 06 Sep 2007 11:12:05 +0100
Subject: RE: request for WG to adopt draft-chadwick-webdav-00.txt as a work item
Thread-Topic: request for WG to adopt draft-chadwick-webdav-00.txt as a work item
Thread-Index: AcfwXghPB8JjBL5SSIOURRaJIt/GsQADpMUg
Message-ID: <A15AC0FBACD3464E95961F7C0BCD1FF006A25BDE5E@EA-EXMSG-C307.europe.corp.microsoft.com>
References: <20070906121635.134112cf@garlique.algebras.org>
In-Reply-To: <20070906121635.134112cf@garlique.algebras.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by balder-227.proper.com id l86ACN8M021032
Sender: owner-ietf-pkix@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: c0bedb65cce30976f0bf60a0a39edea4

Thanks for bringing this up George.

As for all solutions to problems where there already exist other solutions to the same problems, it is important to determine why we need another solution to the same problem.

There is a value to have a limited standardized set of ways to do things as it makes interoperability easier. Sometimes we choose to offer multiple solutions anyway, mostly to enable re-use of existing infrastructures.

I would like to hear more about why it is important to add this to the menu of repository solutions and revocation mechanisms.

My personal concern about the presented approach is that it changes the trust mechanism for certificate revocation from signed objects (CRLs and OCSP responses) to trust in a repository infrastructure. That is, if I get a certificate in return from an expected location it is supposed to be valid. Yet, when revoked a 1 post CRL is examined making revocation CRL based. I don't think this fits with the model of CRL processing described in section 6.3 of RFC 3280.


Stefan Santesson
Senior Program Manager
Windows Security, Standards


> -----Original Message-----
> From: owner-ietf-pkix@mail.imc.org [mailto:owner-ietf-
> pkix@mail.imc.org] On Behalf Of George Michaelson
> Sent: den 6 september 2007 08:47
> To: ietf-pkix@imc.org
> Subject: request for WG to adopt draft-chadwick-webdav-00.txt as a work
> item
>
>
>
> I am very interested in the construction of a systematic framework for
> webdav based publication protocols to be used to publish into
> repositories. Other WG areas of work are considering adoption of
> certificate based models which require large, distributed repositories
> to be maintained, and will imply a repository provisioning protocol.
>
> I therefore wish to propose the WG adopt draft-chadwick-webdav-00.txt
> as a work item.
>
> I would also like to ask that the document be slightly modified, to
> present two distinct parts in the proposal
>
> 1) that part which documents use of WEBDAV as a repository publication
>    protocol and the use of a REST model.
>
> 2) that part which discusses naming of the repository objects in the
>    repository, eg for use in the SIA and AIA fields, and the related
>    REST model name mapping.
>
> The reason I ask that it be re-worked in this way is that there are
> other models of repository naming architecture which do not have
> 'deep' RDN name structure in the certificate Subject name, and are less
> ameanable to a deterministic mapping as Dave has proposed. If the
> document is re-worked slightly to make it plain that this is only one
> of many repository naming models, it will be easier for related work to
> cite this document in reference to part 1) use of WEBDAV and to draw up
> a distinct repository name mapping function reflecting part 2) in
> spirit.
>
> I have some very minor concerns with stipulating the correct TLS
> version to support virtual webhost naming in a secured connection to
> the server during WEBDAV binding. I am sure these can be very easily
> addressed.
>
> Thanks to Dave Chadwick for writing this draft, and presenting it at
> IETF69 Chicago.
>
> -George