[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: COPS-TLS extensions
Hi,
You are correct in your observation that these are the responsibilities
of the application that implements TLS.
What are the extensions you are proposing? Please post them to this
list.
Thanks,
Amol
-----Original Message-----
From: geg01@uow.edu.au [mailto:geg01@uow.edu.au]
Sent: Monday, July 28, 2003 8:30 PM
To: rap@ops.ietf.org
Subject: COPS-TLS extensions
Hello
Im am a student studying the use of COPS-PR for distributing
firewall security policies over insecure networks. I thus
far have a working Java implementation of COPS-PR and COPS-
TLS however some issues have come to my attention regarding
TLS session re-use/caching policies for COPS-TLS, as well as
policies governing re-handshaking to renew keying material
at an appropriate interval.
From my understanding, it is the responsibility of the
application that implements TLS to handle these issues, so
for my work I am proposing some minor extensions to COPS-TLS
that allow greater control over the underlying TLS. Just
wandering if anyone has addressed these issues in the past,
or if it is a pointless idea.
Many thanks