Re: Domain certificates in SIP (complete)
2007-07-02 13:40:36 GMT
[the last copy escaped early(Continue reading)] On Sat, 2007-06-23 at 16:46 -0400, Scott Lawrence wrote: > draft-gurbani-sip-domain-certs-05 has been submitted to > the IETF archives. We've tried to incorporate some of the advice we got > around the Prague meeting. > > This version focuses fairly narrowly on: > > - How to use and interpret the SIP identities in a X.509 certificate. > - How to indicate that this particular certificate is for SIP > usage. > > What goes in the subjectAltName, and a new EKU value, with the detailed > steps to interpret and validate them are provided from the viewpoint of > user agents, proxies, and registrars. > > Until the -05 version appears in the archives, you can get it from: > > http://svn.resiprocate.org/rep/ietf-drafts/gurbani/domain-certs/draft-gurbani-sip-domain-certs-05.txt > http://svn.resiprocate.org/rep/ietf-drafts/gurbani/domain-certs/draft-gurbani-sip-domain-certs-05.html > > Comments, questions and other feedback is much appreciated. The authors would particularly appreciate some expert PKIX review on whether or not the usage of the suggested Extended Key Usage reasonable and (at least potentially) effective? This is described in sections 5 and 8.1:
]
On Sat, 2007-06-23 at 16:46 -0400, Scott Lawrence wrote:
> draft-gurbani-sip-domain-certs-05 has been submitted to
> the IETF archives. We've tried to incorporate some of the advice we got
> around the Prague meeting.
>
> This version focuses fairly narrowly on:
>
> - How to use and interpret the SIP identities in a X.509 certificate.
> - How to indicate that this particular certificate is for SIP
> usage.
>
> What goes in the subjectAltName, and a new EKU value, with the detailed
> steps to interpret and validate them are provided from the viewpoint of
> user agents, proxies, and registrars.
>
> Until the -05 version appears in the archives, you can get it from:
>
>
RSS Feed