OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

dss message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [dss] Approach to code-signing profile


Title: Message
Agreed.  What key's are used by the service should be pretty flexible to allow for various biz models.  For example not only should we separate the key used to sign the request from the service key, but the framework should also not constrain a single requestor to a single key.
 
Regards,
Alex
 
-----Original Message-----
From: Pieter Kasselman [mailto:PKasselman@betrusted.com]
Sent: Tuesday, January 20, 2004 8:38 AM
To: 'Nick Pope'; Pieter Kasselman; dss@lists.oasis-open.org
Subject: RE: [dss] Approach to code-signing profile

Hi Nick

Without getting to philosophical about it, I would prefer to separate the request for a signature from the ownership of the key. Ownership tends to be a business relationship as opposed to a request/response protocol which is easy to define. In other words, I think both scenarios need to be supported by the profile.

Cheers

Pieter



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]