[Uta] Re: [TLS] Re: Is there any interest in an RFC on how to do cross-organization mTLS?

2024-09-10 Thread John Mattsson
I would be very supportive of such approach. I think the scope should cover mTLS in general, not just cross-organization. The term mTLS is not even defined in IETF, in fact the TLS WG has previously used mTLS for at two other things. It would be good to a document to refer to for implementation

[Uta] Re: [TLS] Is there any interest in an RFC on how to do cross-organization mTLS?

2024-09-10 Thread Olle E. Johansson
I agree here. The term “mTLS” is used more and more and there’s no specification. If we could document a few profiles for it, like internal use in a system, cross-organisation etc that would be beneficial. /O > On 10 Sep 2024, at 09:16, John Mattsson > wrote: > > I would be very supportive o

[Uta] Re: [TLS] Re: Is there any interest in an RFC on how to do cross-organization mTLS?

2024-09-10 Thread Iyer, Sudha E
I agree. It is also good to cover different reference models / recommended patterns for mTLS vs one-way TLS. Best, Sudha E Iyer | Head, Data CyberSecurity Architecture Team|Chief Information Security Office| sudha.e.i...@citi.com