Re: [E-CARM] PKI, CAs, TTPs &c.


Unless I badly misunderstand you, this is one reason for the existence
of the SPKI working group.  It begins with the notion, illustrated by
the design, implementation, and subsequent operations of the Internet
itself, that centralized control structures don't scale.  From there it
observes that the verifier of a message is the ultimate root authority,
and thus that all authority which it recognizes effectively flows from
itself.  My interest in SPKI has always been from the perspective of
wanting standardized code to do what must otherwise be accomplished with
lots of custom coding for each type of authorization.  PKIX is clearly
not interested in this; they are already committed to using X.509 to do
the job.  The cert-talk list is probably not interested in this either;
the emphasis there seems to be concentrating on applying existing products
and standards.

I think it's a very good thing to talk about.


