2 Nov 2000 15:50
Holder (was Re: Comments on draft-ietf-pkix-ac509prof-05.txt)
Steve Hanna <steve.hanna <at> sun.com>
2000-11-02 14:50:45 GMT
2000-11-02 14:50:45 GMT
We now have 11 possible formats for the Holder field:
1) baseCertificateID only
2) entityName only
3) baseCertificateID and entityName
4) objectDigestInfo only with publicKey hash
5) objectDigestInfo only with publicKeyCert hash
6) baseCertificateID and objectDigestInfo with publicKey hash
7) baseCertificateID and objectDigestInfo with publicKeyCert hash
8) entityName and objectDigestInfo with publicKey hash
9) entityName and objectDigestInfo with publicKeyCert hash
10) baseCertificateID, entityName, and objectDigestInfo with publicKey
hash
11) baseCertificateID, entityName, and objectDigestInfo with
publicKeyCert hash
Given that we're designing a *profile* of X.509 ACs, can we choose one
or two of these formats, recommend that AC issuers only use those, and
require that AC verifiers be able to process them? If not, then I'm
afraid interoperability will be impossible.
Let's see if I can narrow things down a bit. I'll start by pointing out
that using objectDigestInfo with publicKeyCert hash may cause problems
if the holder wants to use a different PKC to authenticate than the one
whose hash is in the AC. Using objectDigestInfo with publicKey hash
should resolve the concern raised by Polar (problems with inconsistent
or duplicative naming). So I suggest that we not recommend the use of
formats 5, 7, 9, and 11 above.
Is there any reason *not* to include a publicKey hash in the Holder?
(Continue reading)
RSS Feed