[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: COPS-TLS extensions



Hi,

You are correct in your observation that these are the responsibilities
of the application that implements TLS.

What are the extensions you are proposing? Please post them to this
list.

Thanks,
Amol

-----Original Message-----
From: geg01@uow.edu.au [mailto:geg01@uow.edu.au] 
Sent: Monday, July 28, 2003 8:30 PM
To: rap@ops.ietf.org
Subject: COPS-TLS extensions

Hello
Im am a student studying the use of COPS-PR for distributing 
firewall security policies over insecure networks. I thus 
far have a working Java implementation of COPS-PR and COPS-
TLS however some issues have come to my attention regarding 
TLS session re-use/caching policies for COPS-TLS, as well as 
policies governing re-handshaking to renew keying material 
at an appropriate interval.

From my understanding, it is the responsibility of the 
application that implements TLS to handle these issues, so 
for my work I am proposing some minor extensions to COPS-TLS 
that allow greater control over the underlying TLS. Just 
wandering if anyone has addressed these issues in the past, 
or if it is a pointless idea.

Many thanks