Re: [pkix] Simple Certificate Enrollment Protocol (SCEP)

"Sill, Alan" <alan.sill@ttu.edu> Tue, 14 October 2014 16:21 UTC

Return-Path: <alan.sill@ttu.edu>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F5261A87AF for <pkix@ietfa.amsl.com>; Tue, 14 Oct 2014 09:21:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.687
X-Spam-Level:
X-Spam-Status: No, score=-2.687 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.786, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iMPwbJCmSOYS for <pkix@ietfa.amsl.com>; Tue, 14 Oct 2014 09:21:45 -0700 (PDT)
Received: from epona03.ttu.edu (epona03.ttu.edu [129.118.201.76]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 709181A8901 for <pkix@ietf.org>; Tue, 14 Oct 2014 09:21:45 -0700 (PDT)
Received: from empusa09.ttu.edu (129.118.201.66) by mail.ttu.edu (129.118.201.76) with Microsoft SMTP Server id 14.3.181.6; Tue, 14 Oct 2014 11:21:44 -0500
Received: from CYCLOPS04.ttu.edu ([169.254.3.143]) by empusa09.ttu.edu ([129.118.201.66]) with mapi id 14.03.0181.006; Tue, 14 Oct 2014 11:21:44 -0500
From: "Sill, Alan" <alan.sill@ttu.edu>
To: Paul Hoffman <paul.hoffman@vpnc.org>
Thread-Topic: [pkix] Simple Certificate Enrollment Protocol (SCEP)
Thread-Index: Ac/nmCuBb1Xr+ImVQUWYJscmK+kLJwAMg8eAAAiMY4AAAhtGAA==
Date: Tue, 14 Oct 2014 16:21:43 +0000
Message-ID: <56E5D78C-1D42-4A14-9CC7-B90D49A36735@ttu.edu>
References: <9A043F3CF02CD34C8E74AC1594475C739B9CAF27@uxcn10-tdc05.UoA.auckland.ac.nz> <001001cfe7a0$52f31640$f8d942c0$@x500.eu> <10AA61E0-BC44-4515-822D-8C9885C9D7EE@vpnc.org>
In-Reply-To: <10AA61E0-BC44-4515-822D-8C9885C9D7EE@vpnc.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [129.118.242.5]
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <365C2B0BF24A7E41A374210139D5FDAF@default.ttu.edu>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-TechMail-Edge-Route: TTU
Archived-At: http://mailarchive.ietf.org/arch/msg/pkix/msBPhMC0SGuDWy3w_vepmWBKiEM
Cc: Søren Peter Nielsen <soren.peter.nielsen@gmail.com>, Carsten Strunge <CAS@energinet.dk>, PKIX <pkix@ietf.org>, "WG15@iectc57.org" <WG15@iectc57.org>
Subject: Re: [pkix] Simple Certificate Enrollment Protocol (SCEP)
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Oct 2014 16:21:53 -0000

On Oct 14, 2014, at 10:21 AM, Paul Hoffman <paul.hoffman@vpnc.org> wrote:

> If the "smart grid security folks" want to reference a well-written certificate enrollment protocol, they should stay the heck away from SCEP and point to EST.

With this in mind, I would appreciate some informed commentary from this group on the article by John Foley covering this topic in the September 2014 issue of Linux Journal:

http://www.linuxjournaldigital.com/linuxjournal/september_2014/?pg=62&pm=2&u1=friend

(You can close the subscription pop-in window to view the entire article, as it is an open article.)

It refers to a Cisco test server, but otherwise appears to be a very general technical treatment on implementing EST.

Thanks,
Alan