transaction
Click on the red underlined text to get to the source
...
This document describes and identifies the requirements for
transactions to handle PKC lifecycle transactions between [IPsec ...
... This document describes and identifies the requirements for
transactions to handle PKC lifecycle transactions between [IPsec] VPN
...
... PKI Systems. This
document contains requirements for a transaction-based approach.
Other models are conceivable, for example, a directory-centric
approach, but their requirements ...
... Public Key Certificate
(PKC) lifecycle transactions between different VPN System and PKI
System products in order to better enable large scale, PKI-enabled ...
... update, revoke, and confirm), and repository lookups. These
transactions enable a VPN Operator to:
...
... to the pre-agreed template). These authorizations can occur
either prior to the enrollment or in the same transaction as the
enrollment.
...
... The document addresses requirements on transactions between the VPN
Systems and the PKI Systems ...
... excluded, but are intentionally not a focus.
Only VPN-PKI transactions that ease and enable scalable PKI-enabled
IPsec ...
... VPN Administrator to Peer
transactions will not be addressed. These interactions are
considered vendor proprietary. These interactions may be
...
... vendors, but are far beyond the scope of this current effort, and
will be described as opaque transactions in this document.
The protocol specification ...
... management profile. Requirements for [I] transactions
are beyond the scope of this document. Additionally, the act of
certification ...
... Secure Transactions ...
... management profile MUST specify the [A], [E],
[L], and [R] transactions between VPN and PKI Systems. To support
...
... VPN and PKI Systems. To support
these transactions, the Admin and PKI MUST exchange policy details,
identities, and keys. As such, the method ...
... identities, and keys. As such, the method of communication for [A],
[E], and [L] transactions MUST be secured in a manner that ensures
privacy, authentication ...
... trust be established
between the PKI and the Admin (see Section 3.7.1). [R] transactions
do not require authentication or message data ...
... PKCs and CRLs) are already digitally signed.
Whether [R] transactions require privacy is determined by the local
security policy.
...
... management profile will not specify [G]
transactions. However, these transactions MUST be secured in a
manner that ensures privacy ...
... profile will not specify [G]
transactions. However, these transactions MUST be secured in a
manner that ensures privacy, authentication ...
...
Availability is REQUIRED initially for authorization transactions
between the PKI and Admin. Further availability is required in most
...
... A PKC used for identity in VPN-PKI transactions MUST include all the
[CERTPROFILE] mandatory fields. It MUST also contain contents
...
... profile) are the same so that one PKC could be used for
both transaction sets. If the profiles are inconsistent, then
different PKCs ...
... VPN-PKI transactions MUST specify error handling
for each transaction. Thorough error condition descriptions and
handling instructions will greatly aid interoperability ...
...
The authorization scenario for VPN-PKI transactions involves a two-
step process: an authorization request and an authorization ...
... Figure 4 shows the salient interactions to perform authorization
transactions.
+--------------+ +-----------------------+
...
... Thorough error condition descriptions and handling instructions MUST
be provided to the Admin for each transaction in the authorization
process. Providing such error codes ...
...
1) Opaque transaction [G]. Admin sends command to Peer to generate
key pair, based on parameters provided in the command.
...
... Thorough error condition descriptions and handling instructions MUST
be provided for each transaction in the key generation and PKC
request construction process. Providing such error codes ...
...
4) Opaque Transaction [E]. The Admin forwards the enrollment
response back to the IPsec Peer.
...
...
5) Opaque Transaction [E]. Peer positively acknowledges receipt of
new PKC back to the Admin.
...
...
8) Opaque Transaction [E]. Admin forwards PKI's enrollment
confirmation receipt back to the Peer.
...
...
3) Opaque Transaction [E]. The Admin forwards the enrollment
response back to the IPsec Peer.
...
...
4) Opaque Transaction [E]. Peer positively acknowledges receipt of
new PKC back to the Admin.
...
...
7) Opaque Transaction [E]. Admin forwards PKI's enrollment
confirmation receipt back to the Peer.
...
...
3) Opaque Transaction [E]. The Admin forwards the enrollment
response back to the IPsec Peer, along with the keys.
...
...
4) Opaque Transaction [E]. Peer positively acknowledges receipt of
new PKC back to the Admin.
...
...
7) Opaque Transaction [E]. Admin forwards PKI's enrollment
confirmation receipt back to the Peer.
...
...
2) Opaque Transaction [E]. The Admin forwards the enrollment
response back to the IPsec Peer, along with the keys.
...
...
3) Opaque Transaction [E]. Peer positively acknowledge receipt of
new PKC back to the Admin.
...
...
6) Opaque Transaction [E]. Admin forwards PKI's enrollment
confirmation receipt back to the Peer.
...
... Thorough error condition descriptions and handling instructions are
REQUIRED for each transaction in the enrollment process. Providing
such error codes will greatly aid interoperability ...
... Thorough error condition descriptions and handling instructions are
required for each transaction in the rekey, renewal, or update
...
... PKC it wishes to revoke. Whether the actual
revocation request transaction occurs directly with the PKI or is
first sent to Admin (who proxies ...
...
The profile MUST identify the one protocol or transaction within a
protocol to be used for both Peer and Admin initiated revocations.
...
...
Below are guidelines for revocation in specific transactions:
- AFTER RENEW, BEFORE EXPIRATION: The PKI ...
... Thorough error condition descriptions and handling instructions are
required for each transaction in the repository lookup process.
Providing such error codes ...
... Thorough error condition descriptions and handling instructions are
required for each transaction in the revocation checking and path
validation ...
