1 Oct 2011 22:36
SIP identity and SIP domain certs
Olle E. Johansson <oej <at> edvina.net>
2011-10-01 20:36:14 GMT
2011-10-01 20:36:14 GMT
The SIP identity RFC 4474 talks about "SIP Domain certificates" but doesn't really specify the syntax. There's a lot of text about them and parts are a bit confusing, mixing "host name" with "domain". It mentions "subject alt names" in one part, but not in the important parts that only talks about the "Subject" of the certificate. The SIP domain certificates RFC approaches this (RFC 5922) but says clearly: The discussion in this document is pertinent to an X.509 PKIX- compliant certificate used for a TLS connection; this document does not define use of such certificates for any other purpose (such as Secure/Multipurpose Internet Mail Extensions (S/MIME)). So this document does not update RFC 4474 because it only talks about TLS connections, not certificates for domains for signing. It seems like the idea is to have multiple certificates, which sounds impractical. One for HTTPS, one for SIP/TLS and another one for SIP Identity. Shouldn't RFC 5922 really have updated RFC 4474 so we got a better specification of the actual X.509v3/PKIX certificate used for Identity headers? /O
RSS Feed