EricssonResearch / ace-ake-authz

Other
0 stars 1 forks source link

Omit example of certificate enrollment #12

Closed gselander closed 2 years ago

gselander commented 2 years ago

In this document we consider the target interaction for which authorization is needed to be "enrollment", for example joining a network for the first time (e.g. [RFC9031]), or certificate enrollment (such as [I-D.selander-ace-coap-est-oscore]), but it can be applied to authorize other target interactions.

Since certificate enrollment can also be carried out with CSR in EAD_3, I propose we remove this part to avoid confusion:

or certificate enrollment (such as [I-D.selander-ace-coap-est-oscore]),

malishav commented 2 years ago

Removed this mention with 094b91583d

There is one more mention of CSR in 4.4.3.1:

EAD_3 MAY contain a certificate enrollment request, see e.g. CSR specified in {{I-D.mattsson-cose-cbor-cert compress}}, or other request which the device is now authorized to make.

Do you want to remove this mention as well?

gselander commented 2 years ago

I propose we keep that. I was concerned about having both descriptions could be confusing. Since this describes another use case of EAD, which is relevant to LAKE, I think is the most relevant to keep.