Kemp, David P. wrote:
But if one is going to create a new mechanism for sharing state among multiple devices that make up a single service/application, it seems more elegant to give that service a unique identifier (such as an RFC 4122 UUID) rather than to create a new cert with a cross-reference to a bunch of other certs.
Wouldn't it be more appropriate to use attribute certificates for sharing the state (if the public-key itself is not an essential part of the state)?
Ciao, Michael.