Re: New Version Notification for draft-seantek-ldap-pkcs9-04.txt
Sean Leonard <[email protected]> Wed, 16 Mar 2016 07:13:56 -0700
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Message-ID | <[email protected]> |
On 3/16/2016 6:34 AM, Simo Sorce wrote: > On Tue, 2016-03-15 at 19:11 +0000, Barry Leiba wrote: >> Yes, I had thought this might wait for a resurrection of an ldapext >> working group, but that seems to have stalled. I'm happy to >> AD-sponsor this to get the registration done, but I'd like some review >> and comment from the LDAP folks, and this is the place for that. Will >> some of you please take a look at Sean's draft and comment? > I haven't done proper full review, but I thought aliases was frowned > upon these days and I see quite a few one(few) char aliases in there, > why do we need such aliases ? This draft documents the existing practice of security implementations, including MS CryptoAPI and OpenSSL. This should be evaluated through the lens of "backwards or long-term systems compatibility", not the lens of "these days" (in the LDAP community). PKIX enabled systems (read: OpenSSL) use LDAP strings (RFC 4514) to serialize and de-serialize the Distinguished Names in certificates. Parity is required and the only registry is the LDAP Parameters / Object Identifier Descriptors registry. These strings have migrated to cross-systems protocols. See, e.g., draft-martin-authentication-results-tls. Using "e" for emailAddress = 1.2.840.113549.1.9.1, for example, is simply an historical fact. This reminds me, I should probably include a note about "gn" (givenName) in a future draft. Best regards, Sean > > Simo. > >> Thanks, >> Barry, ART AD for another few weeks >> >> On Sat, Mar 12, 2016 at 5:23 PM, Sean Leonard <[email protected]> wrote: >>> This is a friendly reminder that the LDAP PKCS #9 registration >>> Internet-Draft is still a live issue. >>> >>> Sean >>> >>> -------- Forwarded Message -------- >>> Subject: New Version Notification for draft-seantek-ldap-pkcs9-04.txt >>> Date: Sat, 12 Mar 2016 09:20:32 -0800 >>> From: [email protected] >>> >>> >>> >>> A new version of I-D, draft-seantek-ldap-pkcs9-04.txt >>> has been successfully submitted by Sean Leonard and posted to the >>> IETF repository. >>> >>> Name: draft-seantek-ldap-pkcs9 >>> Revision: 04 >>> Title: Lightweight Directory Access Protocol (LDAP) Registrations >>> for PKCS #9 >>> Document date: 2016-03-12 >>> Group: Individual Submission >>> Pages: 7 >>> URL: >>> https://www.ietf.org/internet-drafts/draft-seantek-ldap-pkcs9-04.txt >>> Status: https://datatracker.ietf.org/doc/draft-seantek-ldap-pkcs9/ >>> Htmlized: https://tools.ietf.org/html/draft-seantek-ldap-pkcs9-04 >>> Diff: >>> https://www.ietf.org/rfcdiff?url2=draft-seantek-ldap-pkcs9-04 >>> >>> Abstract: >>> PKCS #9 includes several useful definitions that are not yet >>> reflected in the LDAP IANA registry. This document adds those >>> definitions to the IANA registry. >>> >>> _______________________________________________ >>> Ldapext mailing list >>> [email protected] >>> https://www.ietf.org/mailman/listinfo/ldapext >> _______________________________________________ >> Ldapext mailing list >> [email protected] >> https://www.ietf.org/mailman/listinfo/ldapext >