Re: [dix] Permanent IDs and how to obsolete an identity
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [dix] Permanent IDs and how to obsolete an identity




Lisa,

I think its virtually impossible to remove anything completely from the Web.

I think we should concentrate on expiring the credentials associated with IDs.   Driver's licenses and passports
have expiration dates.  PKI certs have expiration dates and revocation lists.  Most ID's do not, and I think this is
a feature that is sorely needed.

Thus "permanent IDs are not allowable" might be a better approach.



Charles Carrington
cdcarr at us.ibm.com


Lisa Dusseault <lisa at osafoundation.org> wrote on 04/28/2006 03:23:28 PM:

>
> Somebody was talking to me about how IDs similar to  
> "myname at serviceprovider.com" are useless because you can't trust the  
> ID when the service provider is gone.
>
> Isn't it the general expectation that these IDs are impermanent?  
> Just like when my email address at work becomes obsolete when I leave  
> the job -- I just stop using that ID.  In fact it may be easier to  
> obsolete an ID than an email address.  OTOH it might not be, there  
> might be permissions and preferences scattered about the Web,  
> associated with an ID that suddenly becomes useless.
>
> The statement that "permanent IDs are not required" might be useful  
> in the charter.  There may also be interesting use cases about how to  
> obsolete an ID.
>
> Lisa
>
> _______________________________________________
> dix mailing list
> dix at ietf.org
> https://www1.ietf.org/mailman/listinfo/dix
_______________________________________________
dix mailing list
dix at ietf.org
https://www1.ietf.org/mailman/listinfo/dix

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.