[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: X509 ACs - Too late, too little



> 
> I.e. if you want to discuss XML-ACs you must do it somewhere else?
> Even if it addresses the very same applications and "market" as X509 ACs?

It might be interesting to see whether one could use an enhanced version of
XER in order to have a natual XML encoding of X.509 certs, i.e. being able
to have a pure XML encoding of an X.509 cert or other asn1 signed data with
a special xml signature canonicalisation that creates the DER encoding from
the XER encoding in order to verify the signature. 

Would this be a work item for PKIX?