Re: [sidr] Subject names wrt sidr-ta, sidr-arch
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [sidr] Subject names wrt sidr-ta, sidr-arch



On Mon, 13 Apr 2009, Terry Manderson wrote:

For no meaningful names:
	CPS isn't constructed to do identity checks on the resource recipient
Subordinate CAs may adopt a different CPS and make naming inconsistent
...
So, in this light I would urge the authors to remove all requirements for ANY RPKI certs to be named, including the higher order RPKI certs.

I concur.

As convenient as is surely would be to have meaningful names for IANA and the RIRs, there's nothing eventiny another entity from issing certs with those names, and surely some tools will be written that check the names rather than the keys. Let's not lead the tool writers into such temptation.

-- Sam



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.