RE: On trusting presence intermediaries

"Mark Day" <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
> While this issue is straightforward for instant messaging, presence
> presents problems.  In my opinion, a certificate should contain
> subject alternative names that identify subjects in an actual system,
> not the ones in the model defined in RFC 2778.  For example, if one
> server is signing all presence information that comes from one domain,
> I believe it should have one identifier that allows it to perform
> this, and only this function.  There is nothing new here, we've
> already been over this.

We have indeed "already been over this" but I'm not sure we've ever
established with any precision the answer to the following question:

Why is it important to support an implementation in which one server signs
all presence information from one domain?

It's not clear to me why that's an especially desirable arrangement (the
actual trust implications are somewhat obscure to me), but I'm not claiming
any special expertise on the point.  Even if the answer is painfully obvious
to you, I suspect that I and others would benefit from a somewhat more
detailed explanation.

--Mark






  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.