Re: AW: Errors and Questions

     I agree with you.  I don't see why we should shift from having lots of
certificates allowed, with no guaranteed relationship between them, to
having only the EE certificate allowed and not allowing chains.  It makes
more sense, IMO, to set requirements on which certificates are allowed
along the lines of some earlier suggestions - for example, allowing only
one EE certificate and requiring that all other certificates be part of a
certification chain for that one.  We could even require that there be only
one chain and that the certificates appear in leaf-first order - it would
still be better than just a leaf and it would not be very hard to

          Tom Gindin

"Gregor Karlinger" <> on 07/27/2000 03:54:06

Sent by:

To:   "Gregor Karlinger" <>, "Barb Fox"
      <>, "Joseph M. Reagle Jr." <>
cc:   "XML" <>, "Brian LaMacchia"
Subject:  AW: Errors and Questions

Sorry, I hit the  wrong key on my keyboard, and the message was gone ...

Hi Barb,

 > [GK20]Only a single certificate possible  here?  [Barb]  Yes. One per

Please see my comment on [GK20] in my  previous message:

Regards,  Gregor
Gregor  Karlinger
Phone +43 316  873 5541
Institute for Applied Information Processing and  Communications

Received on Friday, 28 July 2000 14:55:05 UTC