Re: [TLS] A proposal for a new field in delegated credentials

2020-03-04 Thread Paul Yang
> On Mar 4, 2020, at 6:51 AM, Martin Thomson wrote: > > > On Tue, Mar 3, 2020, at 18:10, Paul Yang wrote: >> In such a case, it's possible to utilize delegated credentials to >> subsititue X.509 certificate in the 'inner' service mesh communication, >> but we found something is missing in cu

Re: [TLS] A proposal for a new field in delegated credentials

2020-03-03 Thread Martin Thomson
On Tue, Mar 3, 2020, at 18:10, Paul Yang wrote: > In such a case, it's possible to utilize delegated credentials to > subsititue X.509 certificate in the 'inner' service mesh communication, > but we found something is missing in current structure of the > definition of the 'Credential'. In ser

[TLS] A proposal for a new field in delegated credentials

2020-03-02 Thread Paul Yang
Hi there, As mentioned in "Delegated Credentials for TLS" draft, we found this feature is mainly designed for application-to-service scenario - for instance, to replace the so-called 'keyless' solution. By applying delegated credential, external CA could be less depended so that one can issue c