Re: On trusting presence intermediaries

Graham Klyne <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
At 08:48 AM 8/29/02 -0400, John D. Ramsdell wrote:
>Graham seems to suggest that we could use the hierarchy implied by
>certificate chains to specify certificates that can be used to sign
>for all the subjects that own certificates it issued.

That is not what I was suggesting.  In particular, I'm not suggesting some 
kind of master certificate, which your text seems to imply.

Rather, I'm suggesting that a user can sign a new certificate to delegate 
some authority vested in it to the wielder of some other key.

>... I believe that
>hierarchy is meant to be used for another purpose.  It allows
>certificates to be issued at different locations without the sharing
>of private keys.

I think the scheme I suggested is a variation of that idea (for some 
variant of "different locations").

#g


-------------------
Graham Klyne
<[email protected]>




  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.