Re: Work around using SPKI certificates instead of X509


>>>>> "SALLE" == SALLE Mathias <matsal@hplb.hpl.hp.com> writes:
    SALLE> REFERENCE: ipsec drafts, SPKI drafts PROBLEM: Is it
    SALLE> possible to use ISAKMP/Oakley to establish an SA and at the
    SALLE> same time exchange users SPKI certificates, this in a
    SALLE> context of a Host to Host mode.

    SALLE> QUESTION: Is there any work around using SPKI certificates
    SALLE> instead of X509 certificates in ISAKMP?

    SALLE>  If no, would it be possible to use Certificate Request
    SALLE> Payload and Certificate Payload to exchange SPKI
    SALLE> certificates? Is there any drafts on that?

  There is a certificate type in ISAKMP for SPKI. The format of it has
not been defined. I would suggest that one could either put multiple
SPKI certs (in binary form), just pasted together, or better, a
(sequence ...) of them.

  See isakmp-10, page 34.

  A draft defining a SPKI certificate tag for IPsec SA's would be a
wonderful thing.

