Re: XML certificate ...

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

At 08:58 PM 5/9/00 -0400, Gunther Schadow wrote:
>As the world reinvents everything using XML, might it not be time to do
>the same with certificates?  I think the world of certificates could 
>use a big shake-up.  Getting rid of X509 and ASN.1 would be a huge 
>reduction of burdon on any security implementation. It would make 
>certificate generation and interpretation a snip of a finger. 

There is a proposal, delivered at the IETF meeting in Australia, for an XML 
native encoding of SPKI (and therefore the other formats as well, since SPKI 
includes the other two functionalities).

>Compatibility with X509, SPKI, and PGP certificate products could be
>provided through XMLifying translators.

The problem with a translator is that signatures don't translate.

If you're worried about internal mode, we have one defined for CDSA that 
carries the information of all three of the formats.  For more on that, see 
the CDSA spec and especially the AuthCompute module. (Authorization 
Computation)

 - Carl


-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.0.2

iQA/AwUBORm5ocxqBGb+WvJAEQLnhwCfTaGoTzREW5i8/yQV5b4Se1UTkzQAn38b
q4mDVhBUvnfClhw8ypGQbLZU
=DCdl
-----END PGP SIGNATURE-----


+--------------------------------------------------------+
|Carl Ellison      Intel             E: cme@jf.intel.com |
|2111 NE 25th Ave  M/S JF3-212       T: +1-503-264-2900  |
|Hillsboro OR 97124                  F: +1-503-264-6225  |
|PGP Key ID: 0xFE5AF240              C: +1-503-819-6618  |
|  1FDB 2770 08D7 8540 E157  AAB4 CC6A 0466 FE5A F240    |
+--------------------------------------------------------+

Received on Wednesday, 10 May 2000 15:33:55 UTC