I believe you that the certificate format is agnostic on the subject
of
hierarchy. When I talk about hierarchy (in the last year or so), I'm
careful to refer to X.500 or PEM rather than X.509. Of course, the
hierarchy is enshrined elsewhere (X9.57, for example) and remains in
the
minds of the reader from years of PEM talk.
Needless to say, I think PKIX would benefit from eliminating all DN
fields
and even the definition of DN in the certificates to be proposed (X.509v4?).
That would be a good start towards unification of the efforts (which
will
probably happen at some point, many years from now, since we're both
pursuing the truth, not matter how much old baggage we are carrying).
Im not willing to wait several years; Im planning for a world of three
standards:
X.509 id certs, X.509 attribute certs, and SPKI-certs acting as an
openCapability.
X.509 att-certs and id-certs instances are currently linked via
the commonality
of name forms (whichever name-form is chosen.) and the correpondence
of
a given value.
I would now like to link SPKI-certs and (X.509 id-certs and X.509 att-certs)
similarly.
This is not a proposal for SPKI-certs to change their format: rather
it is a proposal for there to be a standard linkage mechanism, basedon
use of the SDSINameForm and the role it plays in its namemanagement model.
I would like your consent to reference the SPK cert document's <name>
form
definition, and an approval that this would make such an X.509 cert
conform to the ideas of SPKI local-naming and security concepts (when
used in
consort with an SPKI-chain reduction).
-----
Here is my example of a practical and useful intersection between the
two
worlds, whicih are otherwise independently managed except for
mutual use of a name-form and values:-
bob, alice and freda are all subscribers to a single X.509 certification
domain, and its formal policy obligations on all.
skywalker is a portending SPKI verifier who receives an SPKI cert chain
vouching for the name "bob's alice's freda"
Skywalker, wishing to reduce the SPKI cert chain for classical
security controls , and during this process (below) wishing to optionally
obtain third-party control benefits,
(a) uses the X.509 id-certs from third-party (CA) to
establish that 'bob is bob' and is indeed bound to the CA policy.
Similary for
alice, and freda.
(b) obtains a CA-issued cert for the reduced-name "skywalker's (bob's
alice's freda)"
in order that skywalker can demonstrate the acceptance of the act
and consequences of auth-fields reduction to a third-party during dispute
handling, and that
all four parties are indeed agreeing to be bound to the [disputed
resolution elements
of the] policy, in the context of the reduced the auth field.
- Carl
+------------------------------------------------------------------+
|Carl M. Ellison cme <at> cybercash.com http://www.clark.net/pub/cme
|
|CyberCash, Inc. http://www.cybercash.com/
|
|207 Grindall Street PGP 2.6.2: 61E2DE7FCB9D7984E9C8048BA63221A2 |
|Baltimore MD 21230-4103 T:(410) 727-4288 F:(410)727-4293 |
+------------------------------------------------------------------+