W3C home > Mailing lists > Public > www-xkms@w3.org > March 2002

RE: I'll have salad with my key...

From: Hallam-Baker, Phillip <pbaker@verisign.com>
Date: Wed, 6 Mar 2002 08:55:45 -0800
Message-ID: <2F3EC696EAEED311BB2D009027C3F4F4058699C3@vhqpostal.verisign.com>
To: "'stephen.farrell@baltimore.ie'" <stephen.farrell@baltimore.ie>, www-xkms@w3.org
Steve's example is far from frivolous.

I spent a bit of time working through the issues surrounding putting
people's pictures in their certificate. I don't think it is acceptable for
privacy reasons, you need more control over who can access the image. XKMS
is a means to provide that control.

Of course this is out-a-scope at present except to the extent that there is
the necessary extensibility mechanism.

There are basically two ways to get extensibility in XML (that I am prepared
to talk about anyways). One is the ##any approach, the other is to use the
type extension (qua inheritance) mechanism.

Since we have no FINAL types (except perhaps KeyUsage if we want to make
absolutely sure there is no possibility of a non-repudiation bit), all the
types are extensible.

If we are going to go for extensibility we should seriously consider using
the SAML style inheritance.


Phillip Hallam-Baker FBCS C.Eng.
Principal Scientist
VeriSign Inc.
781 245 6996 x227

> -----Original Message-----
> From: Stephen Farrell [mailto:stephen.farrell@baltimore.ie]
> Sent: Tuesday, March 05, 2002 12:43 PM
> To: www-xkms@w3.org
> Subject: I'll have salad with my key...
> Joseph worried:
> > The KeyBinding is not extensible, what if I want to query or return 
> > different trust semantics than those provided by XKMS?
> Well, given that it contains a ds:KeyInfo and I can put my granny's
> photo in there, what more do we need?
> Stephen.
> -- 
> ____________________________________________________________
> Stephen Farrell         				   
> Baltimore Technologies,   tel: (direct line) +353 1 881 6716
> 39 Parkgate Street,                     fax: +353 1 881 7000
> Dublin 8.                mailto:stephen.farrell@baltimore.ie
> Ireland                             http://www.baltimore.com

Received on Wednesday, 6 March 2002 11:54:57 UTC

This archive was generated by hypermail 2.3.1 : Tuesday, 6 January 2015 20:31:38 UTC