Re: On trusting presence intermediaries
Graham Klyne <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
At 08:48 AM 8/29/02 -0400, John D. Ramsdell wrote: >Graham seems to suggest that we could use the hierarchy implied by >certificate chains to specify certificates that can be used to sign >for all the subjects that own certificates it issued. That is not what I was suggesting. In particular, I'm not suggesting some kind of master certificate, which your text seems to imply. Rather, I'm suggesting that a user can sign a new certificate to delegate some authority vested in it to the wielder of some other key. >... I believe that >hierarchy is meant to be used for another purpose. It allows >certificates to be issued at different locations without the sharing >of private keys. I think the scheme I suggested is a variation of that idea (for some variant of "different locations"). #g ------------------- Graham Klyne <[email protected]> [reminder: [email protected] for non-technical discussions, please]