Re: [Emu] Review of draft draft-ms-emu-eaptlscert-02

2019-05-08 Thread Alan DeKok
On May 8, 2019, at 7:16 AM, Anoop Kumar Pandey wrote: > >> The reality is that there are some organizations who treat certificates as a >> dumping ground for information. > > 3 Tier chained certificate with organization validated certificate in DER > encoded Binary mode has a size of just 1588

Re: [Emu] Review of draft draft-ms-emu-eaptlscert-02

2019-05-08 Thread Anoop Kumar Pandey
tificate caching or certificate compression, that will also take time. Or if the customer insists or reports, OEM will have to provide firmware upgrade or device replacement with new protocol implemented. Regards, Anoop -----Original Message- From: Alan DeKok [mailto:al...@deployingradius.

Re: [Emu] Review of draft draft-ms-emu-eaptlscert-02

2019-05-06 Thread Alan DeKok
On May 6, 2019, at 6:47 AM, Anoop Kumar Pandey wrote: > Section 3 talks about various reasons for a certificate being large. Subject > Alternative Name field is typically used for multi-domain or wildcard > certificates (fb.com, *.facebook.om, facebook.net, messenger.com) where all > domains ar

[Emu] Review of draft draft-ms-emu-eaptlscert-02

2019-05-06 Thread Anoop Kumar Pandey
Draft Review (draft-ms-emu-eaptlscert-02) Title: Handling Large Certificates and Long Certificate Chains in TLS-based EAP Methods URL: https://tools.ietf.org/html/draft-ms-emu-eaptlscert-02 Description: The draft talks about large TLS certificates with long certificate chains. This may result i