[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Deprecate the NR bit?



Title: RE: Deprecate the NR bit?
I agree we should not deprecate the bit; there are coherent
application contexts, including NATO X.400 secure inter-personal
and organizational messaging service,  and Authenticode. Neither
of these contexts deviate from the ISO NR definitions and intent.
 
We should remove any "mandatory requirement" for
use of the NR-bit in IETF std protocols/profiles, however.
 
Use of the NR bit should always be an operational
choice; it is helpful if operational context(s)
is/are signaled in the enhancedKeyUsage field.
 
Any PKIX language which implies a dependency between
use of the NR bit and any other key usage bit, should be
ignored for the purpose of compliance testing.
-----Original Message-----
From: Fillingham, David W. [mailto:dwfilli@missi.ncsc.mil]
Sent: Friday, August 27, 1999 9:51 AM
To: 'Stefan Santesson'; 'Linn, John'
Cc: 'ietf-pkix@imc.org'
Subject: RE: Deprecate the NR bit?

I agree with John and Stefan that the NR bit not be deprecated, for the reasons they indicate, and because the current draft DoD Certificate Policy has slightly different requirements for certificate generation and management for digital signature certificates that do or do not assert the non-repudiation key usage bit.

Dave Fillingham