[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Public key validation and Proof of possession
At 3:18 PM -0400 10/26/05, Russ Housley wrote:
Steve:
If I understand your proposal, you are suggesting a certificate
policy OID that would be included in the certificate (in addition to
any other certificate policy OID that is appropriate). This would
be acceptable to me if it was only used in end-entity certificates.
I think it could add complication to certificate policy mapping,
which is already too messy.
I note that the certificate policy OID does not offer the same
granularity. The OID would only be included if the public key
validation is performed and proof of possession is performed.
Russ
I envisioned two policies, one for each of PoP and PKV.
However, If Stefan's observation about policies is correct (I admit
to having not checked first), then this is not a viable alternative
to your proposal, even independent of the policy mapping complexity
concerns your cited.
Steve