Re: [sidr] I-D Action:draft-ietf-sidr-res-certs-16.txt
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [sidr] I-D Action:draft-ietf-sidr-res-certs-16.txt
I've just finished my read of version 16.
* Section 3.9.5
With the introduction of Extended Key Usage, can I suggest that the
wording follow that of RFC5280 for consistency in how key purposes are
constructed?
e.g:
Object identifiers used to identify key purposes MUST be assigned in
accordance with IANA or ITU-T Recommendation X.660 [X.660].
I also agree that the EKU should be there. It provides a level of
extensibility.
* Removal of section 6.3
I could not agree more! TA structures are so important in this
application that they should stand as a topic (*draft*) in their own
right.
* section 7 Design Notes
firstly " yet still ensure that the structures Subject name changes",
I think should be
"structure's"
secondly - I had to re-read this paragraph several times to simply
understand that the advise is to have CAs which use a constant CN per
entity still change their DN via the serial number at key rollover.
yeah? Any way this can be revised for us dummies? ;)
* personal nit:
The word uniqueness bugs me ;-) something is either unique or it is
not. There are no varying degrees of being unique. I'd love to see a
different word or phrase used - but it isn't a blocker for me.
Cheers
Terry
On 26/02/2009, at 8:00 AM, Internet-Drafts at ietf.org wrote:
A New Internet-Draft is available from the on-line Internet-Drafts
directories.
This draft is a work item of the Secure Inter-Domain Routing Working
Group of the IETF.
Title : A Profile for X.509 PKIX Resource Certificates
Author(s) : G. Huston, et al.
Filename : draft-ietf-sidr-res-certs-16.txt
Pages : 34
Date : 2009-02-25
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.