Re: [Emu] Idea: New X509 Extension for securing EAP-TLS

2019-11-13 Thread Jan-Frederik Rieckers
There has been some discussion about this idea. I don't have any experience in IETF work yet, so I don't know how this discussion can go on. I would be happy to present my deployment experiences from eduroam and the basic idea in Singapore. (Since I won't attend the meeting in person, I would join

Re: [Emu] Idea: New X509 Extension for securing EAP-TLS

2019-11-13 Thread Michael Richardson
On 2019-11-13 4:07 a.m., Alan DeKok wrote: > On Nov 12, 2019, at 11:43 AM, Russ Housley wrote: >> Can the extended key usage for EAP over a LAN ( id-kp-eapOverLAN ) solve >> this for you? It is defined in RFC 4334. A certificate for Web PKI should >> not include this extended key usage. >>

Re: [Emu] Idea: New X509 Extension for securing EAP-TLS

2019-11-13 Thread Michael Richardson
On 2019-11-13 7:40 a.m., Alan DeKok wrote: > On Nov 12, 2019, at 3:13 PM, Cappalli, Tim (Aruba) wrote: >> How does a public CA prove ownership of an SSID? > Do public CAs *always* verify addresses and/or telephone numbers, which are > normally included in certificates? They are?  I've rarely