[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: cA flag and CRL issuers (was Re: Last Call: draft-ietf-pkix-new-part1-06.txt comments)
Dave,
I provided an analysis of the evolution of CRL signing from V1 + V2
certs, to the changes you cite re V3 certs. You have chosen to
ignore large parts of this analysis, and focus on text in the current
version of X.509 that emphasizes syntactic details but not the larger
semantic context. You have not adressed the fact that both X.509 and
RFC 2459 make repeated references to "authorities" or CAs re CRL
issuance. You have received feedback from Sharon, and I think several
of the 2459 authors have weighed in on this topic during the
multi-week debate.
I see no point in continuing the discussion.
Steve