2 Jul 2012 19:23
Re: IPsec, APIs, and x.500 naming (Re: Should security requirements be MUST?)
Nico Williams <nico <at> cryptonector.com>
2012-07-02 17:23:42 GMT
2012-07-02 17:23:42 GMT
On Mon, Jul 2, 2012 at 11:46 AM, Stephen Kent <kent <at> bbn.com> wrote: > Two observations: > - one need not use the subject name for access control decisions > - one can represent a DNS name as Subject name, using the DC > attribute The former would be nice, but since that's not what's implemented, it's not really possible to issue certificates with meaningless (unique, effectively pseudonymous) subjectNames. The latter works for only one name type, and it's a hack. But that's the point: being forced to use the useless Name type means we're forced to encode better name types as Name using ad-hoc conventions. x.500-style naming is stupid and worse than useless -- it is harmful. Nico --
RSS Feed