/
EMU and DANE EMU and DANE

EMU and DANE - PowerPoint Presentation

myesha-ticknor
myesha-ticknor . @myesha-ticknor
Follow
385 views
Uploaded On 2016-03-14

EMU and DANE - PPT Presentation

Jim Schaad August Cellars EMU TLS Issues Trust Anchor Matching PKIX cert to EMU Server Name Certificate Revocation Checking CRLs OCSP DANE Review Use DNS as alternative or secondary trust framework ID: 255463

dane tls trust ocsp tls dane ocsp trust emu extension stapling anchor matching certificate record addresses records fix pass responder naming domain

Share:

Link:

Embed:

Download Presentation from below link

Download Presentation The PPT/PDF document "EMU and DANE" is the property of its rightful owner. Permission is granted to download and print the materials on this web site for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.


Presentation Transcript

Slide1

EMU and DANE

Jim Schaad

August CellarsSlide2

EMU TLS Issues

Trust Anchor

Matching PKIX cert to EMU Server Name

Certificate Revocation Checking

CRLs

OCSPSlide3

DANE Review

Use DNS as alternative or secondary trust framework

New Records for cert/public key information

Naming: _<port>._<protocol>.<Domain Name>

Matching:

Trust Anchor (Root)

CA

EESlide4

DANE Stapling

Addresses Trust Anchor Issue

Addresses matching Certificate Name

Create a new _

teap

._emu.<Domain Name> DNS record set

Use existing TLSA records

Build list of DNSSEC records and pass in TLS extension

If necessary – new record for name matchingSlide5

OCSP Stapling

Addresses certificate chain validation

Pass OCSP responses in TLS extension

Need to establish trust in OCSP responder

Maybe fix with DANE record

Maybe fix by returning CRLs

Maybe fix by making the Trust Anchor the OCSP responderSlide6

Work List

Need DANE naming convention done in EMU

Need DANE stapling TLS extension – Probably done in DANE

Need OCSP stapling TLS extension done in TLS

Draft-pettersen-tls-ext-multiple-ocsp-03.txtSlide7

Questions?