[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Comments on <draft-ietf-pkix-crlaia-00.txt>
Denis:
Finally! We now uncover the actual point of disagreement.
You say:
The same trust anchor is not a *sufficient* condition. The same node in the
certification tree is the necessary condition. This implies, of course, the
same trust anchor, but since two CRL issuers located at different nodes
(i.e. certified by different CAS) might have the same CRL issuer name, this
condition is insufficient to solve the issue.
When policies, procedures, and practices are followed, I do not believe
that two different CRL issuers that are subordinate to the same trust
anchor can legitimately have the same name. As I said yesterday, I am
willing to add text to the Security Considerations section to state
this. I am even willing to state that certificate users should not include
trust anchors that do not have policies, procedures, and practices that
would prevent such name collisions.
Russ