[saag] Re: pining a certificate/trust anchor
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Yaron Sheffer <[email protected]> wrote: > HPKP (RFC 7469) was effectively obsoleted by the industry, although the > document remains current. You write: A Pin is a relationship between a hostname and a cryptographic identity (in this document, one or more of the public keys in a chain of X.509 certificates). Pin Validation is the process a UA performs to ensure that a host is in fact authenticated with its previously established Pin. and that's very accurate for the context of the document you wrote, but isn't that useful for me. I'm updating RFC8366, and a complaint is that we use the word pin without defining it. RFC8366 vouchers essentially connect a device to the domain[*] which owns it. RFC8672 is an interesting read, but also does not offer a useful definition for my use. [*]- but the DNS reviewers are now upset about our use of that term. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmevWAgWHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZfTHB/9vgSPOr6p5U0X9MxaV93LAi8MH V4j+xWBYQvGJSQ70RdRMVFVud0bf788jd1lKgTERacLi1N/xgUa+I2vnHVMLbArm V5aXYjto5vY+/2EklGn7AjZOdBgB8uYMC2Czg/FltpxgEvhflYRCauwpSirWxCaw nMX/sW/gHd4OZiOBc0MtaKiqTVMw25DR6TtJusp1l/c4rEPznuFqrW+djWojqADJ 8aucRGIJCgNImlJfuz/+EnlhMcyWMyB+wLcd0xSUrYfIqmR/4TeWOTOdqZa684X4 Oadk/Ay9PG773nkUaMuxk28SzBVVOxdTl5FJI0XLZ2xGzuInrKRLuLfPkNe+ =u0ad -----END PGP SIGNATURE-----