[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Missing Protocol ?



> 
>      Some comments.  I think we can get a lot of this into certificates or
> CMP responses, if we don't try for a "universal solution".  If liability is
> at issue, even one of the ID's should do the trick.  The only problem I see
> is a privacy problem.  If something shouldn't be in a certificate, which
> RP's should be allowed to get it?  If ordinary unprivileged RP's are
> allowed to get it, why (other than certificate lifetime considerations)
> shouldn't it be in the certificate?
> 
'Ordinary' i.e., non-authorised RPs are NOT allowed to access to such data.