[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: lifetime versus NR, Re: Comments on the PKIX Roadmap




Sean Turner wrote:

> We'll update the NR discussion in the draft roadmap, but could you enumerate your other
> concerns?  I think most of the ones I've seen so far dealt specifically with the NR bit
> discussion.

The NR discussion involved not only the question of multiple NR meanings, but also the
ordering of NR meanings in "strength", the encoding of NR meanings in keyUsage bits
and/or in policy extensions, the independence/dependence of NR upon CAs, and the
perception that "intent" was not the issue in NR at all -- since NR can make a latter
provably false act to be binding (e.g., a false signature that cannot be distinguished from
a true signature when presented).

Besides, the CRL and the timestamp discussions had also IMO some interesting points
which I missed in the new roadmap.  If this would be useful, I could review them in some
time and present a list -- however, their main dialogue parties could do this much better
and faster, I believe.

Cheers,

Ed Gerck