[Ace] Re: IoT certificate profile vs TLS SNI and subjectAltName

2025-01-07 Thread Michael StJohns
Working off of https://www.ieee802.org/secmail/msg00396.html EUI-MAC-OtherNames-2025 { iso(1) identified-organization(3) dod(6) internet(1) security(5)     mechanisms(5) pkix(7) id-mod(0) id-mod-pkix1-eui-mac-othername-00 (tbd0)} DEFINITIONS BEGIN IMPORTS OTHER-NAME FROM PKIX1Implicit-2009 {

[Ace] I-D Action: draft-ietf-ace-pubsub-profile-11.txt

2025-01-07 Thread internet-drafts
Internet-Draft draft-ietf-ace-pubsub-profile-11.txt is now available. It is a work item of the Authentication and Authorization for Constrained Environments (ACE) WG of the IETF. Title: Publish-Subscribe Profile for Authentication and Authorization for Constrained Environments (ACE) Autho

[Ace] Fwd: New Version Notification for draft-ietf-ace-pubsub-profile-11.txt

2025-01-07 Thread Cigdem Sengul
Hello everyone, We have uploaded a new version with minor modifications before the document expiration date: Version -10 to -11 * Recommended /ps/TOPICNAME as path ot topic resources at the Broker. * The request for a new Sender ID uses the method POST. * Fixed description of ACE Gr

[Ace] Re: [Uta] IoT certificate profile vs TLS SNI and subjectAltName

2025-01-07 Thread Achim Kraus
Hi Michael, > TL;DR> Help us avoid stuffing non-DNS strings into >SubjectAltName dNSName when doing device to device (D)TLS. I may fail to understandiung your question or intention. Maybe you clarify it. Your initial question in "draft-tls13-iot" was: "I was looking for a SN, or SAN th