certid Discussion Archive - Thread Index
[Prev Page] [Next Page] [Date Index]
[IETF Mailing List Directory]
[certid List Information]
- Re: [certid] Fwd: RFC 6125 on TLS Server ID Check,
=JeffH
- [certid] Fwd: RFC 6125 on Representation and Verification of Domain-Based Application Service Identity within Internet Public Key Infrastructure Using X.509 (PKIX) Certificates in the Context of Transport Layer Security (TLS),
Peter Saint-Andre
- [certid] IESG approval of draft-saintandre-tls-server-id-check-14,
Peter Saint-Andre
- [certid] What security does SRV-ID add when DNS-ID will always match?,
Matt McCutchen
- <Possible follow-ups>
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
=JeffH
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
=JeffH
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Matt McCutchen
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Paul Hoffman
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Peter Saint-Andre
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Peter Saint-Andre
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Matt McCutchen
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Peter Saint-Andre
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Matt McCutchen
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Matt McCutchen
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Peter Saint-Andre
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Matt McCutchen
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Peter Saint-Andre
- Re: [certid] What security does SRV-ID add when DNS-ID will always match?,
Matt McCutchen
- [certid] Fw: Lars Eggert's No Objection ondraft-saintandre-tls-server-id-check-14: (with COMMENT),
Peter Saint Andre
- [certid] fyi: EFF (TLS/)SSL Observatory discussion list,
=JeffH
- [certid] version -14,
Peter Saint-Andre
- [certid] Review of draft-saintandre-tls-server-id-check-12,
Cullen Jennings
- [certid] version 12,
Peter Saint-Andre
- [certid] applicability of draft-saintandre-tls-server-id-check (was: Gen-ART LC Review...),
=JeffH
- Re: [certid] [Gen-art] Gen-ART LC Review of draft-saintandre-tls-server-id-check-11,
=JeffH
- Re: [certid] Second Last Call: draft-saintandre-tls-server-id-check (...) to BCP,
=JeffH
- [certid] fwd: Re: Second Last Call: draft-saintandre-tls-server-id-check (...) to BCP,
=JeffH
- [certid] regarding re-use,
Peter Saint-Andre
- [certid] EFF (TLS/)SSL Observatory data available,
=JeffH
- Re: [certid] Gen-ART LC Review of draft-saintandre-tls-server-id-check-11,
Jeffrey A. Williams
- Re: [certid] Gen-ART LC Review of draft-saintandre-tls-server-id-check-11,
Peter Saint-Andre
- [certid] SRV-ID examples,
Dan Winship
- [certid] Redesigning security card house?,
ArkanoiD
- [certid] version -11,
Peter Saint-Andre
- Re: [certid] accommodating server-to-server (was: I-D Action:draft-saintandre-tls-server-id-check-10.txt),
=JeffH
- Re: [certid] SSL Labs Survey Data,
=JeffH
- Re: [certid] SSL Labs,
Ivan Ristic
- Re: [certid] [cabfman] fyi: newly revised version: draft-saintandre-tls-server-id-check,
Jeffrey A. Williams
- Re: [certid] [xmpp] Fwd: Fwd: I-D Action:draft-saintandre-tls-server-id-check-10.txt,
Philipp Hancke
- Re: [certid] [cabfman] fyi: newly revised version: draft-saintandre-tls-server-id-check,
Eddy Nigg (StartCom Ltd.)
- [certid] next steps for -tls-server-id-check ?,
=JeffH
- [certid] Fwd: I-D Action:draft-saintandre-tls-server-id-check-10.txt,
Peter Saint-Andre
- [certid] weird CN-IDs (subjectCommonName) in SSL Labs Survey Data,
=JeffH
- [certid] some info from SSL labs cert survey data,
=JeffH
- [certid] fyi: Ivan Ristic / Qualsys SSL Labs release raw data from the Internet SSL survey,
=JeffH
- Re: [certid] fyi: assessment of present compatibility of CN-ID, DNS-ID (SAN:dNSName) by Paul Tiemann (digicert) (was: Need to define "most specific, RDN"),
=JeffH
- [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
ArkanoiD
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
ArkanoiD
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
Martin Rex
- Re: [certid] open issue: wildcards in component fragments,
Matt McCutchen
- Re: [certid] open issue: wildcards in component fragments,
Matt McCutchen
- Re: [certid] open issue: wildcards in component fragments,
Martin Rex
- Re: [certid] open issue: wildcards in component fragments,
Martin Rex
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
Martin Rex
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
Matt McCutchen
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
Joe Orton
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
Martin Rex
- Re: [certid] open issue: wildcards in component fragments,
Matt McCutchen
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
Matt McCutchen
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- Re: [certid] open issue: wildcards in component fragments,
Martin Rex
- Re: [certid] open issue: wildcards in component fragments,
Peter Saint-Andre
- <Possible follow-ups>
- Re: [certid] open issue: wildcards in component fragments,
Jeffrey A. Williams
- Re: [certid] open issue: wildcards in component fragments,
=JeffH
- Re: [certid] open issue: wildcards in component fragments,
Jeffrey A. Williams
- [certid] fyi: assessment of present compatibility of CN-ID, DNS-ID (SAN:dNSName) by Paul Tiemann (digicert) (was: Need to define "most specific RDN"),
=JeffH
- [certid] section 4.6 rewrite (aka: Bad certificate handling),
=JeffH
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Jim Schaad
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Peter Saint-Andre
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Jim Schaad
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Peter Saint-Andre
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Matt McCutchen
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Jim Schaad
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Martin Rex
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Jim Schaad
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Martin Rex
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Jim Schaad
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Martin Rex
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Peter Saint-Andre
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Jim Schaad
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Peter Saint-Andre
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Martin Rex
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
Matt McCutchen
- <Possible follow-ups>
- Re: [certid] section 4.6 rewrite (aka: Bad certificate handling),
=JeffH
- [certid] further discussion of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] user agent redirection is inherently "insecure" (was: Re: review of draft-saintandre-tls-server-id-check-09),
=JeffH
- Re: [certid] [TLS] [secdir] secdir review of draft-saintandre-tls-server-id-check-09,
=JeffH
- Re: [certid] [TLS] [secdir] secdir review of,
Jeffrey A. Williams
- Re: [certid] Bad certificate handling,
=JeffH
- Re: [certid] [TLS] [secdir] secdir review of draft-saintandre-tls-server-id-check-09,
Jeffrey A. Williams
- Re: [certid] [secdir] secdir review of draft-saintandre-tls-server-id-check-09,
Peter Saint-Andre
- Re: [certid] secdir review of draft-saintandre-tls-server-id-check-09,
Peter Saint-Andre
- [certid] fwd: jhut: Re: [secdir] secdir review of draft-saintandre-tls-server-id-check-09,
=JeffH
- [certid] Fwd: secdir review of draft-saintandre-tls-server-id-check-09,
Peter Saint-Andre
- Re: [certid] [Technical Errata Reported] RFC4985 (2520),
Stefan Santesson
- [certid] review of draft-saintandre-tls-server-id-check-09,
Wes Hardaker
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
James Schaad
- Re: [certid] [TLS] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- <Possible follow-ups>
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Stefan Santesson
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Shumon Huque
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Stefan Santesson
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Richard L. Barnes
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Shumon Huque
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Stefan Santesson
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Dave Cridland
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Shumon Huque
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Dave Cridland
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Paul Hoffman
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Shumon Huque
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Stefan Santesson
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Stefan Santesson
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Stefan Santesson
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Stefan Santesson
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- [certid] Why require EKU for certid?,
Paul Hoffman
- Re: [certid] Why require EKU for certid?,
Peter Saint-Andre
- Re: [certid] [TLS] Why require EKU for certid?,
Jim Schaad
- Re: [certid] Why require EKU for certid?,
Martin Rex
- [certid] CN-ID and name constraints,
Matt McCutchen
- Re: [certid] CN-ID and name constraints,
Martin Rex
- Re: [certid] CN-ID and name constraints,
Matt McCutchen
- Re: [certid] CN-ID and name constraints,
Martin Rex
- Re: [certid] CN-ID and name constraints,
Matt McCutchen
- Re: [certid] CN-ID and name constraints (oops),
Matt McCutchen
- Re: [certid] CN-ID and name constraints,
Matt McCutchen
- Re: [certid] CN-ID and name constraints,
Peter Saint-Andre
- Re: [certid] CN-ID and name constraints,
Jim Schaad
- Re: [certid] CN-ID and name constraints,
Peter Saint-Andre
- Re: [certid] CN-ID and name constraints,
Jim Schaad
- Re: [certid] CN-ID and name constraints,
Carl Wallace
- Re: [certid] Why require EKU for certid?,
Henry B. Hotz
- Re: [certid] Why require EKU for certid?,
Peter Saint-Andre
- Re: [certid] Why require EKU for certid?,
Paul Hoffman
- Re: [certid] Why require EKU for certid?,
Peter Saint-Andre
- Re: [certid] Why require EKU for certid?,
Stefan Santesson
- Re: [certid] Why require EKU for certid?,
Paul Hoffman
- Re: [certid] Why require EKU for certid?,
Martin Rex
- Re: [certid] Why require EKU for certid?,
Peter Saint-Andre
- Re: [certid] Why require EKU for certid?,
Stefan Santesson
- Re: [certid] Why require EKU for certid?,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Dave Cridland
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Message not available
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Peter Saint-Andre
- Re: [certid] Review of draft-saintandre-tls-server-id-check,
Martin Rex
[certid] Fwd: Review of draft-saintandre-tls-server-id-check,
Paul Hoffman
[certid] fyi: keyassure@ mailing list - aka tls at dnssec, certs/keys-in-DNS(sec), DKI,
=JeffH
[certid] Fwd: I-D Action:draft-saintandre-tls-server-id-check-09.txt,
Peter Saint-Andre
[certid] action plan,
Peter Saint-Andre
Re: [certid] Last Call: draft-saintandre-tls-server-id-check (Representation and Verification of Domain-Based Application Service Identity in Certificates Used with Transport Layer Security) to Proposed Standard,
Peter Saint-Andre
Re: [certid] Last Call: draft-saintandre-tls-server-id-check,
=JeffH
[certid] [Fwd: Last Call: draft-saintandre-tls-server-id-check (Representation and Verification of Domain-Based Application Service Identity in Certificates Used with Transport Layer Security) to Proposed Standard],
Alexey Melnikov
[certid] wrt -tls-server-id-check "profileability",
=JeffH
[certid] updated CertID spec,
Peter Saint-Andre
[certid] chapter 4.4.5 ...,
Peter Sylvester
[certid] wrt domain names vs hostnames (was: Re: DC should be MUST NOT),
=JeffH
[certid] [Fwd: I-D ACTION:draft-turner-ssl-must-not-01.txt],
Sean Turner
[certid] version -07,
Peter Saint-Andre
[certid] Fwd: Re: [xmpp] #74: user acceptance of non-matching presented identities,
Peter Saint-Andre
[certid] Fwd: Re: [xmpp] #73: client caching of server certificates,
Peter Saint-Andre
[certid] False choice for CN,
Paul Hoffman
[certid] IDNA2008,
Paul Hoffman
[certid] DC should be MUST NOT,
Paul Hoffman
[certid] Need to define "most specific RDN",
Paul Hoffman
- Re: [certid] Need to define "most specific RDN",
Peter Saint-Andre
- Re: [certid] Need to define "most specific RDN",
Bruno Harbulot
- Re: [certid] Need to define "most specific RDN",
Paul Hoffman
- Re: [certid] Need to define "most specific RDN",
Kaspar Brand
- Re: [certid] Need to define "most specific RDN",
Peter Saint-Andre
- Re: [certid] Need to define "most specific RDN",
Martin Rex
- Re: [certid] Need to define "most specific RDN",
Peter Saint-Andre
- Re: [certid] Need to define "most specific RDN",
Love HÃrnquist Ãstrand
- Re: [certid] Need to define "most specific RDN",
Peter Saint-Andre
- Re: [certid] Need to define "most specific RDN",
Kaspar Brand
- Re: [certid] Need to define "most specific RDN",
Ludwig Nussel
- Re: [certid] Need to define "most specific RDN",
Peter Sylvester
- Re: [certid] Need to define "most specific RDN",
Kaspar Brand
- Re: [certid] Need to define "most specific RDN",
Peter Saint-Andre
- Re: [certid] Need to define "most specific RDN",
Kaspar Brand
- Re: [certid] Need to define "most specific RDN",
Paul Hoffman
- Re: [certid] Need to define "most specific RDN",
Kaspar Brand
- Re: [certid] Need to define "most specific RDN",
Nelson B Bolyard
- Re: [certid] Need to define "most specific RDN",
Kaspar Brand
- Re: [certid] Need to define "most specific RDN",
Martin Rex
- Re: [certid] Need to define "most specific RDN",
Nelson B Bolyard
- Re: [certid] Need to define "most specific RDN",
Kaspar Brand
- Re: [certid] Need to define "most specific RDN",
Ludwig Nussel
- Re: [certid] Need to define "most specific RDN",
Nelson B Bolyard
- Re: [certid] Need to define "most specific RDN",
Paul Tiemann
- Re: [certid] Need to define "most specific RDN",
Martin Rex
- Re: [certid] Need to define "most specific RDN",
Nelson B Bolyard
- Re: [certid] Need to define "most specific RDN",
Martin Rex
- Re: [certid] Need to define "most specific RDN",
Peter Saint-Andre
- Re: [certid] Need to define "most specific RDN",
Kaspar Brand
- Re: [certid] Need to define "most specific RDN",
Martin Rex
- Re: [certid] Need to define "most specific RDN",
Shumon Huque
- Re: [certid] Need to define "most specific RDN",
Peter Saint-Andre
- Re: [certid] Name constraints and legacy clients,
Matt McCutchen
- Re: [certid] Name constraints and legacy clients,
Matt McCutchen
- Re: [certid] Name constraints and legacy clients,
Paul Tiemann
- Re: [certid] Need to define "most specific RDN",
Martin Rex
- Re: [certid] Need to define "most specific RDN",
Shumon Huque
- Re: [certid] Need to define "most specific RDN",
Peter Sylvester
- Re: [certid] Need to define "most specific RDN",
Kurt Zeilenga
- <Possible follow-ups>
- Re: [certid] Need to define "most specific RDN",
=JeffH
[certid] What DNS-ID if also using a DNS-SRV?,
Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Martin Rex
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Love HÃrnquist Ãstrand
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Alexey Melnikov
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Paul Hoffman
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Martin Rex
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Shumon Huque
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
SM
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Peter Saint-Andre
- Re: [certid] What DNS-ID if also using a DNS-SRV?,
Alexey Melnikov
[certid] Empty subjects,
Paul Hoffman
[certid] Fwd: I-D Action:draft-saintandre-tls-server-id-check-06.txt,
Peter Saint-Andre
[certid] Domain Components,
Peter Saint-Andre
- Re: [certid] Domain Components,
Paul Hoffman
- Message not available
- Re: [certid] Domain Components,
Alexey Melnikov
- Re: [certid] Domain Components,
Paul Hoffman
- Re: [certid] Domain Components,
Alexey Melnikov
- Re: [certid] Domain Components,
Michael Ströder
- Re: [certid] Domain Components,
Paul Hoffman
- Re: [certid] Domain Components,
Peter Sylvester
- Re: [certid] Domain Components,
Michael Ströder
- Re: [certid] Domain Components,
Paul Hoffman
- Re: [certid] Domain Components,
Michael Ströder
- Re: [certid] Domain Components,
Michael Ströder
- Re: [certid] Domain Components,
Bruno Harbulot
- Re: [certid] Domain Components,
Martin Rex
- Re: [certid] Domain Components,
Peter Sylvester
- Re: [certid] Domain Components,
Martin Rex
- Re: [certid] Domain Components,
Paul Hoffman
- Re: [certid] Domain Components,
Michael Ströder
- Re: [certid] Domain Components,
Peter Sylvester
- [certid] CN-ID in version 6,
Peter Sylvester
- Re: [certid] Domain Components,
Paul Hoffman
- Re: [certid] Domain Components,
Peter Sylvester
- Re: [certid] Domain Components,
Paul Hoffman
- Re: [certid] Domain Components,
Peter Sylvester
- Re: [certid] Domain Components,
Martin Rex
- Re: [certid] Domain Components,
Peter Sylvester
[certid] Fwd: [apps-discuss] draft-saintandre-tls-server-id-check and user overrides,
Peter Saint-Andre
Re: [certid] Comments on draft-saintandre-tls-server-id-check-04,
=JeffH
[certid] Please explicitly disallow unvetted info in subject names,
Nelson B Bolyard
Mail converted by MHonArc