- From: Close, Tyler J. <tyler.close@hp.com>
- Date: Thu, 11 Oct 2007 19:26:16 -0000
- To: <public-wsc-wg@w3.org>
Thomas Roessler wrote: > going through the matching algorithm while folding it in... > > - The current language confuses attributes and fields. I suspect > that you mean the various attributes of the Subject certificate > field. Please confirm. The CN, O, L, ST and C values I refer to are the ones in the set referred to by the Subject field in the end entity certificate. Not sure how to be any more specific about this in PKIXese. > - I notice that you have some rules that concern matching the CN > attribute, but none concerning subjectAltName. I'm happy to > simply track this point as an issue. Could you point me to a document covering the semantics of subjectAltName? Is it in use in X.509 certs on the Web? > Also, I'll open an issue to track the "PKI orthodoxy" remarks that > Hal had made at the face-to-face, and will link to that issue from > the draft. Thanks, --Tyler
Received on Thursday, 11 October 2007 19:40:30 UTC