DNS CERT vs. LDAP (was: RE: PKI and S/MIME)
"Blake Ramsdell" <blake@brutesquadlabs.com> Thu, 14 August 2003 00:29 UTC
Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id UAA12661 for <smime-archive@lists.ietf.org>; Wed, 13 Aug 2003 20:29:37 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h7E05Tqt022386 for <ietf-smime-bks@above.proper.com>; Wed, 13 Aug 2003 17:05:29 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h7E05TCo022385 for ietf-smime-bks; Wed, 13 Aug 2003 17:05:29 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h7E05Sqt022377 for <ietf-smime@imc.org>; Wed, 13 Aug 2003 17:05:28 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Wed, 13 Aug 2003 17:05:25 -0700
From: Blake Ramsdell <blake@brutesquadlabs.com>
To: 'Simon Josefsson' <jas@extundo.com>
Cc: 'Anders Rundgren' <anders.rundgren@telia.com>, ietf-smime@imc.org, "'Sean P. Turner'" <turners@ieca.com>
Subject: DNS CERT vs. LDAP (was: RE: PKI and S/MIME)
Date: Wed, 13 Aug 2003 17:05:24 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAALi1NYFz3CESmkNDht4fEzwEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <ilufzk5ktow.fsf@latte.josefsson.org>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit
> -----Original Message----- > From: Simon Josefsson [mailto:jas@extundo.com] > Sent: Wednesday, August 13, 2003 4:46 PM > To: Blake Ramsdell > Cc: 'Anders Rundgren'; ietf-smime@imc.org; 'Sean P. Turner' > Subject: Re: PKI and S/MIME > > I believe that what is lacking is not a technical solution (DNS CERT > RR, LDAP and SRV, etc) but a guideline document, supported by the > S/MIME community, that you can point at when e-mail application makers > ask question such as the one that started this thread. Yes, this was the way I indeed started this thread ("PKI and S/MIME"), by saying "select relevant other work and profile it for use in the S/MIME interpersonal messaging domain" ;). I think we're on the same page. My only point about LDAP is that I wanted to illustrate some of the criteria for any potential profile by comparing two certificate repository methods, and pointing out what I believe is a relevant difference. > One reason why the DNS CERT solution has been proposed, may be that > the LDAP via SRV idea hasn't been fully documented in a Internet-wide > S/MIME environment, leaving the problem unsolved. But once again, if someone held a gun to my head and told me to try and guess if CERT records and the infrastructure to maintain them would achieve traction before LDAP and SRV records would, I would say LDAP and SRV records. This may be a matter of personal taste, but I like to think that it is a practical answer based on limited experience with managing my own domains. > > as well as administrative tools to upgrade those records that are > > different than typical DNS administration tools. > > Yes, someone, somewhere will have to do work to make the idea happen. I think the question is whether or not "someone, somewhere" for DNS CERT records is better than "been there, done that" for LDAP or other repositories. Blake
- PKI and S/MIME Blake Ramsdell
- Re: PKI and S/MIME Simon Josefsson
- Re: PKI and S/MIME Anders Rundgren
- RE: PKI and S/MIME Blake Ramsdell
- Re: PKI and S/MIME Simon Josefsson
- Re: PKI and S/MIME Simon Josefsson
- DNS CERT vs. LDAP (was: RE: PKI and S/MIME) Blake Ramsdell
- RE: PKI and S/MIME Hallam-Baker, Phillip
- Re: PKI and S/MIME Steve Hole
- RE: PKI and S/MIME Steve Hole
- Re: PKI and S/MIME Steve Hole
- RE: PKI and S/MIME Steve Hole
- RE: PKI and S/MIME Hallam-Baker, Phillip
- RE: PKI and S/MIME Blake Ramsdell
- Re: PKI and S/MIME Simon Josefsson
- RE: PKI and S/MIME Blake Ramsdell
- Re: PKI and S/MIME Steve Hole
- Re: PKI and S/MIME Simon Josefsson
- Re: PKI and S/MIME Steve Hole
- RE: PKI and S/MIME Blake Ramsdell
- Re: PKI and S/MIME Denis Pinkas
- RE: PKI and S/MIME Hallam-Baker, Phillip
- Re: PKI and S/MIME Denis Pinkas