certificate authorities and rdf wrt the naming service

<auto97841-revL73yDgGBWk0Htik3J/[email protected]> Mon, 4 Aug 2003 16:30:17 -0700
Newsgroups gmane.comp.security.invisiblenet.iip.devel
Message-ID <[email protected]>
re: hezekaih's message stating that centralized CAs are bad:

4 points: 
- doing scalable distributed signing / allocation of unique nyms is really
really hard.  really hard.  no.
- we can use multiple CA servers that all have access to the signing
private key who synchronize their db to avoid duplicates of nyms.
- users only hit the CA to sign, not to verify.  the public signing key
is, well, public
- we know users are going to be DoS'ed and DDoS'ed.  We should deal with
it up front rather than wait a year to find out we have a flaw in our
architecture

So, I'm fine with either a single CA server or multiple CA servers. 
I don't think we should go towards distributed signing / allocation of
unique human readable nyms.

re: RDF

I think it'd be cool to allow export of the entries into RDF.  I'm pretty
sure we don't want native RDF for searching, as, well, XML sucks for
searching.  But export I'm cool with.

re: the structure of the naming service entry as co described

That all looks great, just add a signature :)

I think this would be a really good application.  Quite incredibly useful.
 

Co, I look forward to the specs and if theres anything I can do to help,
 lemmie know.

thazzit from me.  
-jrandom



Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
https://www.hushmail.com/services.php?subloc=messenger&l=434

Promote security and make money with the Hushmail Affiliate Program: 
https://www.hushmail.com/about.php?subloc=affiliate&l=427