[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [IETF-PKIX] New Notary Protocol Draft



Robert Zuccherato wrote:
>
> 2. Requirements of the Notary Authority
>
> The Notary Authority is MAY to:

What does this mean? - should it either read "is to:" or "MAY:" ?

(personally, I'd consider "is to:" as being a lot nearer "MUST" than
"MAY" - so it does make quite a difference to the way I perceive what
this point is saying (feel free to tell me why I'm wrong though))

> 7.  Security Considerations
>
> This entire document discusses security considerations.
>
> When designing a notary service, the following considerations have
> been identified that have an impact upon the validity or "trust" in
> the notary token.
>
> 1.  The enclosed certificate is revoked or the signer's key is
>     compromised and the corresponding certificate is revoked before
>     the notary acts upon the request. The notary is MAY to validate
>     appropriate information within the request before it constructs
>     the notary token.  It is therefore mandated that the NA have
>     access to current information regarding certificate status before
>     it creates the token.  In this situation, the notarization process
>     would produce an error.

"is MAY to" again.

Stephen.

--
+-----------------------------------------+----------------------------+
| Stephen Wilson. BSc (hons), AMIEE.      | S.Wilson@eris.dera.gov.uk  |
| Defence Evaluation & Research Agency,   | http://www.dera.gov.uk/    |
| St Andrews Road,                        |                            |
| Malvern,                                | Tel: +44 (0)1684 894153.   |
| WR14 3PS.                               | Fax: +44 (0)1684 896113.   |
| United Kingdon.                         |                            |
+-----------------------------------------+----------------------------+
| Standard disclaimer: "The Information contained in this E-Mail and   |
| any subsequent correspondence is private and is intended solely for  |
| the intended recipient(s). For those other than the intended         |
| recipient any disclosure, copying, distribution, or any action taken |
| or omitted to be taken in reliance on such information is prohibited |
| and may be unlawful."                                                |
+----------------------------------------------------------------------+