[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Public key validation and Proof of possession




At 3:18 PM -0400 10/26/05, Russ Housley wrote:
Steve:

If I understand your proposal, you are suggesting a certificate policy OID that would be included in the certificate (in addition to any other certificate policy OID that is appropriate). This would be acceptable to me if it was only used in end-entity certificates. I think it could add complication to certificate policy mapping, which is already too messy.

I note that the certificate policy OID does not offer the same granularity. The OID would only be included if the public key validation is performed and proof of possession is performed.

Russ


I envisioned two policies, one for each of PoP and PKV.

However, If Stefan's observation about policies is correct (I admit to having not checked first), then this is not a viable alternative to your proposal, even independent of the policy mapping complexity concerns your cited.

Steve