[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ANNOUNCEMENT: SPKI mailing list and BOF at Los Angeles



-----BEGIN PGP SIGNED MESSAGE-----

> I'll give you more time to respond to my proposal -- but the problems I see
> are with the distinguished names themselves:  the concept of having a unique
> identifier of some human being as a prerequisite to generating a certificate.
> 
I had a moderately lengthy discussion with Warwick Ford in the hall outside
  his office today about this issue.  With the X.509 V3 certificate,
  the PKIX group very well *could* recommend a profile of X.509 that
  uses NUL values in the DistinguishedName fields, and uses the
  alternateName types in the standard extensions.  Those extensions
  include provision for many of the favourite "handles" of the
  IETF community--DNS names, rfc822 addresses, etc.

To be fair to X.509, and to the PKIX group, DistinguishedNames are not
  a necessary prerequisite to generating a certificate.

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQBVAwUBMTJZy6p9EtiCAjydAQGbGwH/UudD2p2OpeT8/fBkJtjjnF1jMElgXE1e
IIAfjUL6ytom4caRacD/Hn/9QeV5NvsKc5Lx38YlpviiNjF3zR42GQ==
=mLEd
-----END PGP SIGNATURE-----

--
----------------------------------------------------------------------
Marcus Leech                   Mail: Dept 4C16, MS 238, CAR
Systems Security Architect     Phone   : (ESN) 395-4901  (613) 763-9145
Systems Security Services      Fax     : (ESN) 393-7679  (613) 763-7679
Nortel Technologies            mleech@bnr.ca
-----------------Expressed opinions are my own, not my employers------

References: