Skip to content

Comments on FIA_X509_EXT.1/AuthSvr #21

@jfisherbah

Description

@jfisherbah

FIA_X509_EXT.1/AuthSvr has several comments on it that are being reproduced here for tracking purposes.

  1. Re: extendedkeyusage field - "If IKE extended key usage is not prevalent and this breaks IKE implementations (even if not critical), omit this requirement."
  2. Re: certificates not asserting anyExtendedKeyUsage (OID 2.5.29.37.0) - "See above about IKE key usage potentially breaking implementations."
  3. Re: certificates requiring Client Authentication purpose - "Some rumbling at IETF that this is for “Web” authentication, only and shouldn’t apply for EAP-methods supporting TLS mutual authentication. Poll vendors, and follow IETF to maybe allow other purposes (or none?)."
  4. Re: certificates requiring Server Authentication purpose - "See IETF rumblings about 'web only' above."
  5. Re: certificates requiring ipsec-ike purpose - "Check to see if this is actually used in iPsec products (RFC indicates EKU is not recommended?)."

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions