certificate authorities and rdf wrt the naming service
<auto97841-revL73yDgGBWk0Htik3J/[email protected]> Mon, 4 Aug 2003 16:30:17 -0700
| Newsgroups | gmane.comp.security.invisiblenet.iip.devel |
|---|---|
| Message-ID | <[email protected]> |
re: hezekaih's message stating that centralized CAs are bad: 4 points: - doing scalable distributed signing / allocation of unique nyms is really really hard. really hard. no. - we can use multiple CA servers that all have access to the signing private key who synchronize their db to avoid duplicates of nyms. - users only hit the CA to sign, not to verify. the public signing key is, well, public - we know users are going to be DoS'ed and DDoS'ed. We should deal with it up front rather than wait a year to find out we have a flaw in our architecture So, I'm fine with either a single CA server or multiple CA servers. I don't think we should go towards distributed signing / allocation of unique human readable nyms. re: RDF I think it'd be cool to allow export of the entries into RDF. I'm pretty sure we don't want native RDF for searching, as, well, XML sucks for searching. But export I'm cool with. re: the structure of the naming service entry as co described That all looks great, just add a signature :) I think this would be a really good application. Quite incredibly useful. Co, I look forward to the specs and if theres anything I can do to help, lemmie know. thazzit from me. -jrandom Concerned about your privacy? Follow this link to get FREE encrypted email: https://www.hushmail.com/?l=2 Free, ultra-private instant messaging with Hush Messenger https://www.hushmail.com/services.php?subloc=messenger&l=434 Promote security and make money with the Hushmail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427