Russ Housley wrote: >I do not really care as long as we agree on ONE way to do it. We can come >up with a transition strategy once there is an agreed to standard. I >cannot accept multiple ways to ask for the same stuff.
We need to support userCertificate;binary because that's what the current spec and implementations support. The LDAPBIS working group wants to transition to userCertificate.
I don't think it's possible to meet both of these requirements without having two ways to access the attribute. Why is it so important to only have one way? Wouldn't a smooth transition from userCertificate;binary to userCertificate be preferable? Do you have some better idea? If so, please present it.
Otherwise, I suggest we use Hallvard's simplest solution: New servers MUST support userCertificate or userCertificate;binary and treat them as identical. Clients SHOULD use userCertificate;binary. Once the old servers are gone, we can say that clients SHOULD use userCertificate.
-Steve