[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

PKIX Part I - Name Constraints



I wish to propose a minor addition to 4.2.1.11 (Name Constraints) of PKIX
Part I.  

Regarding RFC822Name, the most common way to convey an e-mail address today
is as a PKCS#9 e-mail attribute in the subject DN.  Migration to
subjectAltNames will undoubtedly occcur in time, and the profile correctly
covers that future.  However, to ensure that the intent of Name Constraints
is met given current styles of naming, I propose that we additionally state
that "Restrictions for the rfc822 name form shall also apply to any
instance of the PKCS#9 E-mail Name attribute type present in a subject DN."

Warwick

---------------------------------------------------------------------
Warwick Ford, VeriSign, Inc., One Alewife Center, Cambridge, MA 02140
   wford@verisign.com; Tel: (617)492 2816 x225; Fax: (617)661 0716
---------------------------------------------------------------------