Re: Beyond HTTP Authentication: OAuth, OpenID, and BrowserID: Meeting on March 29th at IETF83

On 20 Mar 2012, at 10:15, Anders Rundgren wrote:

> There is to my knowledge no SDO who have taken on secure key storage and
> provisioning.  In TCG (which I'm a member of), secure key storage is on
> the menu but the provisioning has been left to vendors to cater for.

*Tangentially related*, I blogged a little bit about secure provisioning the other day:

http://nevali.net/post/19391532575/provisioning-keys-and-provenance

(if memory serves we've talked around this list in the past — so to be clear, I'm not claiming to have invented anything, just written it up)

As with everything, I'm sure there's a terribly good reason why somebody or other wouldn't want to implement such a thing.

M.

-- 
Mo McRoberts - Technical Lead - The Space,
0141 422 6036 (Internal: 01-26036) - PGP key CEBCF03E,
Project Office: Room 7083, BBC Television Centre, London W12 7RJ



http://www.bbc.co.uk/
This e-mail (and any attachments) is confidential and may contain personal views which are not the views of the BBC unless specifically stated.
If you have received it in error, please delete it from your system.
Do not use, copy or disclose the information in any way nor act in reliance on it and notify the sender immediately.
Please note that the BBC monitors e-mails sent or received.
Further communication will signify your consent to this.
					

Received on Tuesday, 20 March 2012 10:21:55 UTC