|
All,
>This really has gotten out of hand. I admire the dedication of folks who have been applying serious intellectual effort to creating a general >formula for cert lifetime as a function of the number of attributes, but ... > >As the creator of "Steve's Rule of Revocation" I have to admit that I generated the simple inverse square formula just to make a point, i.e., that, >in general, adding attributes to a cert will shorten it's effective lifetime and thus is generally a bad idea. I agree with
Steve here. I think this horse is dead now, and I resolve to stop arguing
these points.
>As some have pointed out, a general formula is hard, since one can cite
examples whwre added attributes are so closely linked to existing >attributes
that the addition has no real effect on expected lifetime. Also, contributors to
this thread pointed out early on that it is the attribute >with the shortest
expected lifetime that governs the lifetime of the cert. So, trying to express
the lifetime in terms of a pure attribute count >seems
futile.
> >Now, if I had to justify my original formula, I might try the following analogy: > >1. Adding attributes to a cert is a generally bad idea. In vernacular terms, it "sucks." > >2. Looking to physics for an analogy, we note that, in the vernacular, gravity "sucks." > >3. The inverse square law applies to gravitational attraction between bodies. > >4. Therefore, the effective lifetime of a certificate is inversely propotional to the inverse square of the number of attributes :-) She's a witch! She turned me into a
newt! (I got better)
--bob Bob Blakley (blakley@dascom.com)
Chief Scientist, Dascom |
BEGIN:VCARD VERSION:2.1 N:Blakley;Bob FN:Bob Blakley ORG:Dascom TITLE:Chief Scientist TEL;WORK;VOICE:+1 (512) 458-4037 x 5012 TEL;WORK;FAX:+1 (512) 458-2377 ADR;WORK;ENCODING=QUOTED-PRINTABLE:;;Plaza Balcones=0D=0A5515 Balcones Drive;Austin;TX;78731;USA LABEL;WORK;ENCODING=QUOTED-PRINTABLE:Plaza Balcones=0D=0A5515 Balcones Drive=0D=0AAustin, TX 78731=0D=0AUSA URL: URL:http://www.dascom.com EMAIL;PREF;INTERNET:blakley@dascom.com REV:19990609T181209Z END:VCARD