[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Cert comparison needs AI?



On Mon, 14 Feb 2000, David P. Kemp wrote:
<ed>
> 
> On the other hand, if two certs contain the identical unmistakeable
> identities yet refer to two different physical entities, then the
> identities must not have been so unmistakeable in the first place,
> and the QC has failed to satisfy the requirements of section 2.
> 
> Stefan, could you either delete that paragraph from "Security
> Considerations", or replace it with something like:
> 
>   "A given physical entity may have multiple forms of unmistakeable
>   identity.  It is not necessarily possible to determine by examination
>   that two qualified certificates refer to the same physical entity."
> 

But isn't it the responsibility of the certificate issuing authority to
ensure two qualified certificates never refer to the same physical entity?