[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: 3280bis: CRL validation




Sharon,

I agree that the X.500 model of naming assumes unambiguous names and that X.509, inherits this model. However, in reality, we do not have a global DIT and thus there are no good assurances that CAs operating in different contexts will not issue certs to different entities using the same subject DN. As a result, I think we have to develop standards guidance that acknowledges the potential of DN reuse under different CAs.

Steve