[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: FW: New Liaison Statement, "Liaison to IETF on the removal of upper bound in X.509"
Paul,
Paul Hoffman wrote:
It seems like there are two questions here:
- Do we object to the ITU making the upper bound on DirectoryString
optional
They've been optional since the second edition of X.500. The defect
resolution will make that clearer, as well as steering away from
any specific suggestions for the upper bounds.
- Should we do anything to draft-ietf-pkix-rfc3280bis to reflect that
The answer to the first should be "no, we don't". Russ gave a list that
shows the the ITU has a *long* way to go before it gets rid of the silly
maximum lengths in X.509.
The defect resolution will throw them all out at the same time.
For me, the answer to the second question is "no" because of the large
number of other silly limitations, most notably CommonName being 64
characters.
Aren't these other silly limitations inherited from the upper bounds
in X.500 ? Alignment with X.500 and LDAP would mean removing these
limitations as well.
Regards,
Steven
--Paul Hoffman, Director
--VPN Consortium