[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: 3280bis: CRL validation
Sharon,
I agree that the X.500 model of naming assumes unambiguous names and
that X.509, inherits this model. However, in reality, we do not have
a global DIT and thus there are no good assurances that CAs operating
in different contexts will not issue certs to different entities
using the same subject DN. As a result, I think we have to develop
standards guidance that acknowledges the potential of DN reuse under
different CAs.
Steve