f* wildcards (was: [Fwd: Re: [VCARDDAV] AD review of draft-ietf-vcarddav-carddav-07.txt])
Peter Saint-Andre <stpeter <at> stpeter.im>
2009-09-10 18:48:03 GMT
I just noticed this aspect of a message that Alexey sent to the vCard
list a few weeks ago. I tend to agree with what Alexey reports from a
recent IESG telechat, but I wonder if it will be codified somehow;
perhaps in the server identity checking I-D we've discussed here?
-------- Original Message --------
Subject: Re: [VCARDDAV] AD review of draft-ietf-vcarddav-carddav-07.txt
Date: Mon, 17 Aug 2009 00:02:08 +0100
From: Alexey Melnikov <alexey.melnikov <at> isode.com>
To: Cyrus Daboo <cyrus <at> daboo.name>
CC: CardDAV <vcarddav <at> ietf.org>
References: <4A888C37.50400 <at> isode.com>
<snip/>
3. Requirements Overview
o MUST support secure transport as defined in [RFC2818] using TLS
[RFC5246];
This recently came up in review of
draft-ietf-geopriv-http-location-delivery-15.txt:
RFC 2818, Section 3.1 says:
Matching is performed using the matching rules specified by
[RFC2459]. If more than one identity of a given type is present in
the certificate (e.g., more than one dNSName name, a match in any one
of the set is considered acceptable.) Names may contain the wildcard
(Continue reading)