[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Stray Poll: SerialNumber definition



Anders,

>Anders wrote:
>
> The QC-03 draft does neither specify how serialNumber is to
> be interpreted, nor specify
> how a CA should could inform an RP about its use of serialNumber.
>

This is all wrong.

Section 3.2.5.1 gives you all the tools you need to explicitly define the
nature of the content in the serialNumber attribute.

And you can do more than just identify that the information is unique per
user, you can also identify in what manner the information is unique (World
wide unique, unique per certificate in the issuers domain, unique per
subject in the issuers domain, unique per subject in the specified country
etc).

You can even define exactly the nature of the content (Swedish civic
registration code, Utah drivers license number, etc...)

And more to it, you can name the registration authority (Swedish tax
authority, Utah drivers license registry, etc...)

All of this you already have in QC 03, what else do you need ?


/Stefan