Re: rough sketch of a potential solution

Steve Hole <[email protected]> Tue, 18 Nov 2003 09:12:12 -0700
Newsgroups gmane.ietf.imaa
Message-ID <[email protected]>
On Tue, 18 Nov 2003 10:08:13 -0500 Keith Moore <[email protected]> wrote:


> ... OR to use a certificate that allows alternative 
> names to be associated with the public key (note that the same CA has 
> to be able to make that assertion for all of those names), then I'm 
> happy to dispense with the signature for alternates in the mapping 
> service - as it certainly makes my proposal simpler.

Exactly.  Use certificates the way they were meant to be used and make 
sure that equivalent names are certified as equivalent.   Many MUAs will 
probably treat this properly right now ... I know mine would.    It does 
constrain equivalent addresses to be issued in the same domain, but I 
think that is a good restriction anyway.

Cheers.
---
Steve Hole
Chief Technology Officer - Billing and Payment Systems
ACI Worldwide
<mailto:[email protected]>
Phone: 780-424-4922