Re: [therightkey] Client Certificate Usability (was RE: Will the real RPF please stand up?)

2012-02-08 Thread Ryan Hurst
om: Stephen Farrell [mailto:stephen.farr...@cs.tcd.ie] Sent: Wednesday, February 08, 2012 2:19 PM To: Ben Laurie Cc: Ryan Hurst; Joe St Sauver; therightkey@ietf.org; Stephen Kent Subject: Re: [therightkey] Client Certificate Usability (was RE: Will the real RPF please stand up?) On 02/08/2012

Re: [therightkey] Client Certificate Usability (was RE: Will the real RPF please stand up?)

2012-02-08 Thread Ryan Hurst
here, though I really wish as an industry we could align behind a problem statement and work towards it together instead of having so many competing approaches but it is human nature ;) Ryan From: Ben Laurie [mailto:b...@google.com] Sent: Wednesday, February 08, 2012 9:49 AM To: Ryan Hurst

Re: [therightkey] Client Certificate Usability (was RE: Will the real RPF please stand up?)

2012-02-08 Thread Ryan Hurst
IT I don't expect client certificates to be used outside of closed communities. Ryan -Original Message- From: therightkey-boun...@ietf.org [mailto:therightkey-boun...@ietf.org] On Behalf Of Stephen Kent Sent: Wednesday, February 08, 2012 8:57 AM To: Ryan Hurst Cc: 'Joe St Sauver&#x

Re: [therightkey] Will the real RPF please stand up?

2012-02-07 Thread Ryan Hurst
A very good point, this is also one of the reasons deploying smart card authentication is difficult as well. Today people use IP Phones, mobile phones, tablets, desktops, kiosks and more; moving to a "require" solution for authentication requires one have a solution for all of these devices or you

[therightkey] Client Certificate Usability (was RE: Will the real RPF please stand up?)

2012-02-07 Thread Ryan Hurst
Forking thread as I fee compelled to discuss client certificates but I am not sure its related to the original thread. I also worked on some moderately successful client certificate solutions, their success however was only possible because of the pain tolerance for the communities they served; by