- From: Web Security Context Working Group Issue Tracker <sysbot+tracker@w3.org>
- Date: Wed, 2 Jan 2008 19:05:13 +0000 (GMT)
- To: public-wsc-wg@w3.org
ISSUE-148: Downgrade ability to update an organization's name and address to SHOULD [wsc-xit] http://www.w3.org/2006/WSC/track/issues/ Raised by: Mary Ellen Zurko On product: wsc-xit 7.1 "Both the first check in the matching algorithm and the second to last, which compares the "CN" attributes of the certificates' subject fields, provide a means to transparently update an organization's name and address. " This section would benefit from simplification, at least of the MUSTs. Can we do without that feature, and is that a useful simplification? I think so. It doesn't seem to happen that often. I realize any mismatch between user expectations/abilities and tool model may degrade its security. But I'd still like to argue this aspect is only a SHOULD.
Received on Wednesday, 2 January 2008 19:05:17 UTC