[stir] certificates: short-lived or status
"Peterson, Jon" <jon.peterson@neustar.biz> Wed, 15 March 2017 20:33 UTC
Date: Wed, 15 Mar 2017 20:33:08 +0000
In reaction to the IESG review, and as well, to our own general sense that we're still not ready to mandate any particular direction, we ended up pulling the real-time status check of OCSP out of the last version of stir-certificates. Figuring out how we want to manage certificate freshness, especially in light of certificates assigned to telephone numbers, is probably the last bit about the core STIR work, before we go on to extensions and so forth, that we need to tackle. I'd like to spend some meeting time talking about two approaches, as well as any better ideas anybody comes up with for this. The first is roughly what was in the stir-certificates document previously, which is now captured in: https://tools.ietf.org/html/draft-ietf-stir-certificates-ocsp-00 The other is an approach based on short-lived certificates, which would likely rely on ACME or something similar. I've mocked up a discussion draft for that: https://tools.ietf.org/html/draft-peterson-stir-certificates-shortlived-00 ... though it is still fairly content-free at the moment. I think reviewing what we've done with stir-certs and these two approaches warrants some face-time discussion. Thoughts here on the list beforehand are welcome too. Thanks, Jon Peterson Neustar, Inc.
