Linking certs

Tyler was surprised on last week's call that there wasn't a
good way to link various certs belonging to the same end entity.

I personally hadn't thought about that before and actually
didn't see an obvious way to achieve the result so I've written
up a proposal [1] for a new cert extension that may solve the
problem.

I doubt that this'd be finished in time for us to make much use
of it in the our REC (though one never knows:-) but it might
be useful for a future version, and I'd definitely be interested
in whether or not it looks like something the browser vendors
and CA operators might want.

And of course, any and all comments on the draft are welcome.

Cheers,
Stephen.

PS: The draft is an individual submission, not an official IETF
PKIX WG work item, though I've posted a note to that list too
as they might end up taking it on (or not).

[1] http://tools.ietf.org/html/draft-farrell-pkix-other-certs-00

Received on Saturday, 22 December 2007 14:04:10 UTC