Re: [Ace] Keeping the same key identifier for groups

2019-08-20 Thread Jim Schaad
-Original Message- From: Ace On Behalf Of Ludwig Seitz Sent: Tuesday, August 20, 2019 2:09 AM To: ace@ietf.org Subject: Re: [Ace] Keeping the same key identifier for groups On 19/08/2019 22:40, Jim Schaad wrote: > As Ludwig pointed out during the F2F, it makes far more sense to try >

Re: [Ace] Keeping the same key identifier for groups

2019-08-20 Thread Ludwig Seitz
On 20/08/2019 11:18, Peter van der Stok wrote: Example: If you have a CWT authorizing A for audience Z and you now also need authorization B for audience Z, you should request a CWT for A+B for audience Z, that replaces your previous one. Do I understand? two possibilities: A and B are

Re: [Ace] Keeping the same key identifier for groups

2019-08-20 Thread Peter van der Stok
Example: If you have a CWT authorizing A for audience Z and you now also need authorization B for audience Z, you should request a CWT for A+B for audience Z, that replaces your previous one. Do I understand? two possibilities: A and B are members of audience Z; no new CWT needed B is a new

Re: [Ace] Keeping the same key identifier for groups

2019-08-20 Thread Ludwig Seitz
On 19/08/2019 22:40, Jim Schaad wrote: As Ludwig pointed out during the F2F, it makes far more sense to try and keep an entity using the same key identifier for as long as possible. This is in part to make sure that signing keys do not need to be retrieved if they can be easily cached. In