[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: Need to support non-ASN.1 DPV clients?
There are two questions, should such clients be supported? should they be
supported by PKIX?
I assert that the answer to the first question is yes, the latter no. We
have not submitted XKMS to the PKIX list because (amongst other reasons) the
group have 20 odd drafts to clear from the pipeline as it is.
Furthermore, last time someone submitted a non-ASN.1 spec to the list
someone assumed it must have been a mistake and took the time and trouble to
'correct' it for them.
There is a lot more to XML than a syntax. Simply converting ASN.1 to XML
does not meet the needs of the XML space. Without XML experts you can't
write a spec to meet their needs.
Phill
> -----Original Message-----
> From: Steve Hanna [mailto:steve.hanna@xxxxxxx]
> Sent: Wednesday, January 17, 2001 9:40 AM
> To: Stephen Kent
> Cc: PKIX List
> Subject: Need to support non-ASN.1 DPV clients?
>
>
> Stephen Kent wrote:
> > It sounds like we need to decide whether non-PKI aware,
> > non-ASN.1-capable clients need to be supported. If so,
> we should
> > probably define a set of requirements for such clients
> and include this
> > item in that list. I would suggest that such clients
> are an important
> > group and should be supported.
> >
> > I put this question to the list in my strawman spec over 2
> weeks ago,
> > and have not yet gotten a concrete proposal on how to
> accommodate such
> > clients. I will soon decide that we will NOT support them for now,
> > unless I see such a proposal.
>
> Yes, that question is highlighted in your requirements
> document. As you
> point out there, it is important to resolve this question promptly in
> order to decide on DPV and DPD requirements. But, as you
> pointed out in
> yesterday's email, the question has not been discussed on this mailing
> list in a substantial manner since your requirements document was
> published. Therefore, I'd like to start a thread specifically
> addressed
> to this question:
>
> Do we need to support non-PKI aware, non-ASN.1-capable DPV clients?
>
> Let's settle this now. If you believe that such support is
> necessary and
> should be included in this effort or if you believe that it
> should not,
> please speak up now and explain why or why not.
>
> As for a "concrete proposal", I doubt that it will be hard to come up
> with a proposal if we decide that support for non-ASN.1-capable DPV
> clients is needed.
>
> -Steve
>
> P.S. I will set aside the more specific points we were discussing
> regarding non-ASN.1-capable clients until this more basic question is
> resolved.
>