RE: On the need for presentity set identifiers
"Mark Day" <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
> Maybe I am confusing the issue by calling the thing I want a "presence > service identifier". Let me call it instead a "presentity set > identifier". The identifier names the set of presentities that are > identified by PRES URI's that share the same domain name part. I > think this name is more in line with RFC 2778. A person or service > that possesses an X.509 V3 Certificate with a PRES URI in its > subjectAltName can sign for the named presentity. A person or service > that possesses an X.509 V3 Certificate with a presentity set > identifier in its subjectAltName can sign for any presentity that is > named by an element of the set. The correspondence of this set with a > presence service is immaterial. I understand that this new restatement is offered in good faith as a clarification, and I don't want to seem critical of that impulse to make your point(s) more effectively. But this change doesn't actually help me, and I suspect that it's not all that helpful for the list audience in general. I'd rather get clear what the problem is that is being solved before we start working through the details of the solution and what we call its elements. At this point, I feel that both I and Jon Peterson have analyzed the "Eve attacks Alice and Bob" problem without finding a compelling reason for adding any new identifiers or signatures to formats or protocols. If you think that we missed the point, perhaps we should focus on that before we start discussing PRES URIs and X.509 certificates. --Mark [reminder: [email protected] for non-technical discussions, please]