1 Nov 2010 09:04
Re: SCEP vs CMC vs CMP
Anders Rundgren <anders.rundgren <at> telia.com>
2010-11-01 08:04:46 GMT
2010-11-01 08:04:46 GMT
Peter, Everything you and others say looks perfectly OK to me as long as you don't claim to be targeting mobile phones because the mobile phone market holds the only truly global smart card scheme in existence and smart card provisioning is something PKIX has no previous RFC/I-D experience with. Smart card certificate provisioning 2010 begins with creating a secure session between the container and the issuer which affects the rest of the messaging. AFAIK no standard cryptographic API (which you eventually need to hook the enrollment stuff to), supports secure messaging. Apple's SCEP solution does [presumably] not target SIMs but that also means that it is security-wise inferior. RIM is in fact the only company that has anything remotely useful in this space. Anders Peter Gutmann wrote: > Stefan Santesson <stefan <at> aaa-sec.com> writes: > >> On the SCEP standardization issue it worries me that we have a widely >> deployed protocol that has no stable RFC reference. I think we should change >> that as soon as possible. I know we have said that before (in PKIX meetings) >> but it seems to not happen. What can we change to make it happen? > > That's my concern as well, possibly the most widely-deployed and used cert- > provisioning protocol is the one not deemed worthy of an RFC (I don't know > about CMC use, but CMP is virtually nonexistent). >(Continue reading)
Anders
_______________________________________________
pkix mailing list
pkix <at> ietf.org
RSS Feed