[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Comments on <draft-ietf-pkix-crlaia-00.txt>




Denis:

Finally!  We now uncover the actual point of disagreement.

You say:
   The same trust anchor is not a *sufficient* condition. The same node in the
   certification tree is the necessary condition. This implies, of course, the
   same trust anchor, but since two CRL issuers located at different nodes
   (i.e. certified by different CAS) might have the same CRL issuer name, this
   condition is insufficient to solve the issue.

When policies, procedures, and practices are followed, I do not believe that two different CRL issuers that are subordinate to the same trust anchor can legitimately have the same name. As I said yesterday, I am willing to add text to the Security Considerations section to state this. I am even willing to state that certificate users should not include trust anchors that do not have policies, procedures, and practices that would prevent such name collisions.

Russ