[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: meeting minutes
Stephen Kent wrote:
[snip]
>NEW TOPICS:
>- Timestamp & Notary proposals (Carlisle Adams)
>
>Several folks continuing work on these topics and have published
>an independent draft on these topics. The authors received a fair
>amount of private feedback, and hope to be able to bring forward a
>well-formed proposal. Jeff Schiller gave his permission to bring
>this into the WG, based on the WG having made substantial progress
>on the other work items. Thus we will expand the charter to
>encompass these topics.
This is what occurred during the PKIX sessions at the 42nd IETF meeting
with regards to timestamping; however the above is not the whole story.
Between sessions at the IETF meeting I talked with various people about
the new Internet-Draft (authored by Dave Mills, Todd Glassey, and me)
which extends the NTP protocol towards serving as a vehicle for PKI
certified and secured time ("ephemeral" time; "what time is it *now*?"
time), as well as also providing for *timestamps* of data -- within the
same protocol, essentially as gravy (a different usage, I admit).
I spoke with Jeff Schiller about this. After he'd had a chance to look
over the Internet-Draft (i.e., <draft-mills-ntp-auth-coexist-01.txt>),
we spoke again, very near the end of the IETF meeting. Jeff at that
time suggested that since it was now apparent to him that the issue of
PKI and time goes well beyond the question of timestamps to the issue of
how secure *time itself* can be conveyed over an insecure network, he
thought that perhaps the PKIX working group was not equipped to properly
address this expanded issue -- or at least Jeff thought the IESG ought
to be consulted first on the question before the issue of PKIX handling
it or a separate "time" working group being set up is laid to rest.
Thus the issue stands as far as I know. I've addressed two e-mails to
Jeff since the IETF meeting (on 8 and 21 September) but so far have not
received a reply (I assume it takes time to poll the IESG membership).
I have no particular stake in which way the decision goes (except I
think *some* working group needs to address time *and* timestamping),
but wished to alert you that despite the outcome of the PKIX sessions,
the question of whether PKIX handles it appears not quite settled.
Regards,
Michael McNeil
GMT
memcneil@got.net
1-831-438-7811