[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Cautionary Period Straw Poll




I believe that DPV protocols developed by the PKIX working group ought not include support for a cautionary period.

I belive this because the cautionary period is of no value, and will likely confuse, the principle users of DPV users, namely systems that need to decide immediately whether a signature in front of them should be allowed for identification.

The cautionary period is of some value in DSV, although it is not clear whether or not it will be confusing there as well. Knowing what your trusted DSV server's cautionary period is may or may not useful; knowing what your own cautionary period is useful. DSV should either allow the user to give definitive inputs to the cautionary period calculation from the DSV server, or it should not include the cautionary period at all.

--Paul Hoffman, Director
--Internet Mail Consortium