Re: [sidr] I-D Action:draft-ietf-sidr-res-certs-16.txt
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [sidr] I-D Action:draft-ietf-sidr-res-certs-16.txt



I've just finished my read of version 16.

* Section 3.9.5

With the introduction of Extended Key Usage, can I suggest that the wording follow that of RFC5280 for consistency in how key purposes are constructed?

e.g:
Object identifiers used to identify key purposes MUST be assigned in accordance with IANA or ITU-T Recommendation X.660 [X.660].

I also agree that the EKU should be there. It provides a level of extensibility.

* Removal of section 6.3

I could not agree more! TA structures are so important in this application that they should stand as a topic (*draft*) in their own right.

* section 7 Design Notes

firstly " yet still ensure that the structures Subject name changes", I think should be
"structure's"

secondly - I had to re-read this paragraph several times to simply understand that the advise is to have CAs which use a constant CN per entity still change their DN via the serial number at key rollover. yeah? Any way this can be revised for us dummies? ;)

* personal nit:

The word uniqueness bugs me ;-) something is either unique or it is not. There are no varying degrees of being unique. I'd love to see a different word or phrase used - but it isn't a blocker for me.

Cheers
Terry

On 26/02/2009, at 8:00 AM, Internet-Drafts at ietf.org wrote:

A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Secure Inter-Domain Routing Working Group of the IETF.


	Title           : A Profile for X.509 PKIX Resource Certificates
	Author(s)       : G. Huston, et al.
	Filename        : draft-ietf-sidr-res-certs-16.txt
	Pages           : 34
	Date            : 2009-02-25


Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.