[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

COPS-TLS extensions



Hello
Im am a student studying the use of COPS-PR for distributing 
firewall security policies over insecure networks. I thus 
far have a working Java implementation of COPS-PR and COPS-
TLS however some issues have come to my attention regarding 
TLS session re-use/caching policies for COPS-TLS, as well as 
policies governing re-handshaking to renew keying material 
at an appropriate interval.

From my understanding, it is the responsibility of the 
application that implements TLS to handle these issues, so 
for my work I am proposing some minor extensions to COPS-TLS 
that allow greater control over the underlying TLS. Just 
wandering if anyone has addressed these issues in the past, 
or if it is a pointless idea.

Many thanks