Re: [pkix] Simple Certificate Enrollment Protocol (SCEP)
"Dr. Massimiliano Pala" <massimiliano.pala@gmail.com> Tue, 11 November 2014 01:50 UTC
Return-Path: <massimiliano.pala@gmail.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA0EF1AD3D7 for <pkix@ietfa.amsl.com>; Mon, 10 Nov 2014 17:50:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.59
X-Spam-Level:
X-Spam-Status: No, score=-0.59 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001, T_HK_NAME_FM_DR=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K7d36kkP2YCC for <pkix@ietfa.amsl.com>; Mon, 10 Nov 2014 17:50:26 -0800 (PST)
Received: from mail-wg0-x233.google.com (mail-wg0-x233.google.com [IPv6:2a00:1450:400c:c00::233]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 167021AD3CC for <pkix@ietf.org>; Mon, 10 Nov 2014 17:50:26 -0800 (PST)
Received: by mail-wg0-f51.google.com with SMTP id l18so10246959wgh.24 for <pkix@ietf.org>; Mon, 10 Nov 2014 17:50:24 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; bh=1Z0PhFeFMDF7H3Nrezh4OGRLMAZfQELsHYhJ6kq9C10=; b=Ya6AlLglSWnqeACwPZ+tz+gxn/U0vZuxfoy2c1phDJWv8z191J4TsZfYVuYCvd357l cw5OH82Pl3tjmB/0/rS3H4BWt1rwprbSLhLiv1zy6bn+epjhGLBAANEYtNx4UPo2niFR EuDlEhEIJc2EZykKvbnMzEcKKI+Ouu945H/2D2gso6vFmKjxkkreEHK0DQY4dMaGxZnR oU4bnl+M/lEZ/YubwHVCZfp2jV6EfHkBNoG/HQI76z2zpzEk1C+u4He8sD+C1WCgu/0e +XvoTLA6sKKVBgCo30nOp3oUTFhImRBSWGNQu+TQV+hSr+u659y4qm3mggnbOYGHAfHy tQBg==
X-Received: by 10.180.206.171 with SMTP id lp11mr35069891wic.33.1415670624840; Mon, 10 Nov 2014 17:50:24 -0800 (PST)
Received: from iMassi.local ([2001:67c:1231:998:2daf:6f04:992b:d693]) by mx.google.com with ESMTPSA id r10sm15497691wiy.19.2014.11.10.17.50.22 for <pkix@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 10 Nov 2014 17:50:24 -0800 (PST)
Message-ID: <54616B61.7000307@gmail.com>
Date: Mon, 10 Nov 2014 20:50:25 -0500
From: "Dr. Massimiliano Pala" <massimiliano.pala@gmail.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: pkix@ietf.org
References: <9A043F3CF02CD34C8E74AC1594475C739B9DB295@uxcn10-5.UoA.auckland.ac.nz> <D941FEB2-CC8D-4D9C-9496-F7C28B5E0C41@cisco.com>
In-Reply-To: <D941FEB2-CC8D-4D9C-9496-F7C28B5E0C41@cisco.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: http://mailarchive.ietf.org/arch/msg/pkix/pZ5NSunLUUzRplV_C6hax-yzRFI
Subject: Re: [pkix] Simple Certificate Enrollment Protocol (SCEP)
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Nov 2014 01:50:29 -0000
Hi all, I read the thread for a while. I actually do remember that there was a presentation for SCEP and a request for that to be adopted as a working item in this group that was refused based on the fact that we already have IETF protocols for that. If this argument till stands, than any work on this item (or its successor) should be informational and not WG. However, I think it would be useful to resume a conversation about the status of enrollment protocols - in particular, if the current PKIX WG sponsored RFC are not used in the real world (maybe too complex or too many options?) maybe we should address the issue and work on an easier-to-deploy solution..??? After all, what is the use of a standard if nobody uses it in the real world? If that is the case, I think we need to be humble and admit the limits of the current standards and design a pattern to move forward. It could also be that we like the status quo and leave things as they are today - if the majority of people are happy with what we have today. Can we have a poll about "is there a need to review/amend/simplify PKIX work for certificate enrollment" ? Max Pritikin: I would be interested to meet and talk, can you please include me in the discussion/meetings about this? Last consideration: Although I am not the WG chair, and it is not my role, I would like to keep the discussion in check. I have the impression that the topic is somewhat overloaded with non-technical aspects and I hope we can, instead, focus on technical aspects and on what is needed rather than on how this was handled in the past. Cheers, Max > On Nov 7, 2014, at 1:03 PM, Max Pritikin (pritikin) <pritikin@cisco.com> wrote: > > >> On Oct 29, 2014, at 6:35 AM, Peter Gutmann <pgut001@cs.auckland.ac.nz> wrote: >> >> I've spent the time since the last exchange of messages on this thread talking >> to various SCEP users over their requirements. It turns out that the figure >> I'd previously posted, of half a billion SCEP devices in active use, was >> rather an underestimate. SCEP seems to be pretty much the universal device- >> provisioning protocol for non-PC/laptop devices, including mobile phones, >> SCADA devices, gaming machines, ATMs, firewalls, and so on. It's also been >> described to me as the standard BYOD provisioning protocol, its use for this >> being so widespread that Server 2012 even added new, extra capabilities for >> dealing with BYOD use via SCEP (Windows Server 2008 and 2012 are pretty much >> the standard server implementations for dealing with this sort of thing). As >> one person told me, "if a device speaks anything, it'll speak SCEP". >> >> So, no matter how much Cisco would like to forget about it, it's extremely >> widely used, and there's no sign that this is going to change in the future. >> To paraphrase something someone said many years ago about IBM, "SCEP isn't the >> competition, it's the environment”. > > Agreed! We can’t “forget” about it. This is why we paid so much attention to the process flow of SCEP when designing EST to insure minimal pain. > We also need to be able to move forward to suite-b and better client authentication methods. Thus the reason we had to describe something beyond SCEP (which can’t support these improvements). This led to the specific CMC profile that is EST. > >> >> To that end I'd like to request that the SCEP authors give me (or someone else >> who cares about it, e.g. one of the JSCEP folks) change control over the >> document so that we can finally get this published. I submitted a list of >> changes for the current doc ages ago but things seem to have stalled since >> then (the changes were minor things that have come up in real-world usage, >> clarifications to the doc, places where ~15-year-old remnants still exist next >> to current ones, and just a general cleanup of the neglect that it's had for >> the last decade or so, it still talks about MD5 and single DES for example, >> but doesn't mention that newfangled AES thing that everyone's talking about). >> >> Given that it's been more or less abandoned by Cisco, I'd like to finish the >> editing for it and finally get it published as an RFC so that the vast number >> of devices out there using it, and that will use it in the future, have a >> fixed standard that they can refer back to. > > I’ll be at IETF next week. Lets meet with any interested parties and figure out a path forward. > > A question: How is updating "half a billion SCEP devices” to a new version of SCEP any different than updating them to EST or similar? > > - max > >> >> Peter. > > _______________________________________________ > pkix mailing list > pkix@ietf.org > https://www.ietf.org/mailman/listinfo/pkix
- [pkix] Simple Certificate Enrollment Protocol (SC… Erik Andersen
- Re: [pkix] Simple Certificate Enrollment Protocol… Peter Gutmann
- Re: [pkix] Simple Certificate Enrollment Protocol… Michael Jenkins
- Re: [pkix] Simple Certificate Enrollment Protocol… Erik Andersen
- Re: [pkix] Simple Certificate Enrollment Protocol… Peter Gutmann
- Re: [pkix] Simple Certificate Enrollment Protocol… Anders Rundgren
- Re: [pkix] Simple Certificate Enrollment Protocol… Miller, Timothy J.
- Re: [pkix] Simple Certificate Enrollment Protocol… Peter Gutmann
- [pkix] SCEP Stephen Kent
- Re: [pkix] Simple Certificate Enrollment Protocol… Miller, Timothy J.
- Re: [pkix] Simple Certificate Enrollment Protocol… Jeffrey Walton
- Re: [pkix] Simple Certificate Enrollment Protocol… Paul Hoffman
- Re: [pkix] Simple Certificate Enrollment Protocol… Sill, Alan
- Re: [pkix] Simple Certificate Enrollment Protocol… Stephen Kent
- Re: [pkix] Simple Certificate Enrollment Protocol… Melinda Shore
- Re: [pkix] Simple Certificate Enrollment Protocol… Peter Gutmann
- Re: [pkix] Simple Certificate Enrollment Protocol… Stephen Kent
- Re: [pkix] Simple Certificate Enrollment Protocol… Paul Hoffman
- Re: [pkix] Simple Certificate Enrollment Protocol… Stephen Kent
- Re: [pkix] Simple Certificate Enrollment Protocol… Peter Gutmann
- Re: [pkix] Simple Certificate Enrollment Protocol… Anders Rundgren
- Re: [pkix] Simple Certificate Enrollment Protocol… Max Pritikin (pritikin)
- Re: [pkix] Simple Certificate Enrollment Protocol… Anders Rundgren
- Re: [pkix] Simple Certificate Enrollment Protocol… Jeffrey Walton
- Re: [pkix] Simple Certificate Enrollment Protocol… Anders Rundgren
- Re: [pkix] Simple Certificate Enrollment Protocol… Dr. Massimiliano Pala
- Re: [pkix] Simple Certificate Enrollment Protocol… Anders Rundgren
- Re: [pkix] Simple Certificate Enrollment Protocol… Max Pritikin (pritikin)
- Re: [pkix] Simple Certificate Enrollment Protocol… Dr. Massimiliano Pala
- [pkix] Derived Credentials. Was: Simple Certifica… Anders Rundgren
- Re: [pkix] Simple Certificate Enrollment Protocol… Peter Gutmann
- Re: [pkix] Simple Certificate Enrollment Protocol… Max Pritikin (pritikin)
- Re: [pkix] Simple Certificate Enrollment Protocol… Max Pritikin (pritikin)
- Re: [pkix] Derived Credentials. Was: Simple Certi… Anders Rundgren
- Re: [pkix] Derived Credentials. Was: Simple Certi… Max Pritikin (pritikin)
- [pkix] New Microsoft Enrollment system. Was: Simp… Anders Rundgren
- Re: [pkix] Derived Credentials. Was: Simple Certi… Johannes Merkle
- Re: [pkix] Derived Credentials. Was: Simple Certi… Johannes Merkle
- Re: [pkix] Derived Credentials. Was: Simple Certi… Anders Rundgren
- Re: [pkix] Derived Credentials. Was: Simple Certi… Anders Rundgren
- Re: [pkix] Derived Credentials. Was: Simple Certi… Anders Rundgren