Hi IETF tls list,

I have some problem to solve I believe it is good to make my questions and
proposals here.

I'm from Brazil, here we need to use X.509 certificates to sign electronic
invoices XMLs and to communicate this XMLs through https.

The problem is that the most of emitters pass their certificates (with private
and public keys) to the software companies that communicate this invoices, what
in my point of view it is so insecure, the other problem is that generate a
certificate to the software company authorized to emmit the invoice is so
bureaucratic.

My proposal is to create a service that generates tokens to third applications
use this service to sign, and encrypt data without the certificate, and
introduce an option in the tls protocol to pass the token and the service
address to use it when don't have local cert files.

Does it make sense?

--
Walter Neto

_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to