[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cme@cybercash.com: Re: Delegate]

At 09:40 AM 12/18/96 EST, Ron Rivest wrote:
>>This seems to work well when the recipient is a key.  When the recipient is
>>a (e.g. SDSI) name, then the constraint seems to be either overkill (the name
>>can't even be bound to a key) or underkill (the name owner can bind it to
>>many different names).  
>Sorry, I meant "keys" (the name owner can bind it to many different _keys_.)
>Thanks, Carl...

You're welcome, Ron.

This brings up an interesting question about SDSI.

A SDSI cert issuer can define a group in two different ways: as a set of
<grp-name,mbr-name> member certs
<grp-name,key> person certs

I assume that wasn't intended (since we never discussed it before).

Do you see a problem with that?

 - Carl