Re: [TLS] Summarizing identity change discussion so far

Peter Saint-Andre <stpeter@stpeter.im> Fri, 18 December 2009 02:49 UTC

Return-Path: <stpeter@stpeter.im>
X-Original-To: tls@core3.amsl.com
Delivered-To: tls@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 79E083A6828 for <tls@core3.amsl.com>; Thu, 17 Dec 2009 18:49:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TjzQ8RiTMNiS for <tls@core3.amsl.com>; Thu, 17 Dec 2009 18:49:43 -0800 (PST)
Received: from stpeter.im (stpeter.im [207.210.219.233]) by core3.amsl.com (Postfix) with ESMTP id 6F1AD3A67A8 for <tls@ietf.org>; Thu, 17 Dec 2009 18:49:43 -0800 (PST)
Received: from leavealone.cisco.com (72-163-0-129.cisco.com [72.163.0.129]) (Authenticated sender: stpeter) by stpeter.im (Postfix) with ESMTPSA id 2789A40332; Thu, 17 Dec 2009 19:49:28 -0700 (MST)
Message-ID: <4B2AEDB7.10500@stpeter.im>
Date: Thu, 17 Dec 2009 19:49:27 -0700
From: Peter Saint-Andre <stpeter@stpeter.im>
User-Agent: Thunderbird 2.0.0.23 (Macintosh/20090812)
MIME-Version: 1.0
To: mrex@sap.com
References: <200912172145.nBHLjDUT018568@fs4113.wdf.sap.corp>
In-Reply-To: <200912172145.nBHLjDUT018568@fs4113.wdf.sap.corp>
X-Enigmail-Version: 0.96.0
OpenPGP: url=http://www.saint-andre.com/me/stpeter.asc
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="sha1"; boundary="------------ms030203090503040703000106"
Cc: tls@ietf.org
Subject: Re: [TLS] Summarizing identity change discussion so far
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Dec 2009 02:49:44 -0000

On 12/17/09 2:45 PM, Martin Rex wrote:

> There were two scenarios mentioned where this seems to be a
> regular use case IIRC.  Was it gaming where they were using quite
> short-lived certificates and then XMPP, where they were using
> quite long-lived connections?

Correct, in XMPP we have long-lived connections, where by "long-lived"
we mean connections that might be up for days or weeks or months. We
recently worked to clarify the handling of certificates in the context
of such connections (section 14.2.2.3 of draft-ietf-xmpp-3920bis-04).

Peter

-- 
Peter Saint-Andre
https://stpeter.im/