OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

imi message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [imi] Clarifications to the spec to discuss for our call on Thursday


The certificate chain can produce different results, we have already seen this

Anthony Nadalin | Work 512.838.0085 | Cell 512.289.4122

Inactive hide details for John Bradley ---01/08/2009 08:25:52 AM---Better, thanks Mike.John Bradley ---01/08/2009 08:25:52 AM---Better, thanks Mike.


From:

John Bradley <jbradley@mac.com>

To:

Mike Jones <Michael.Jones@microsoft.com>

Cc:

"imi@lists.oasis-open.org" <imi@lists.oasis-open.org>

Date:

01/08/2009 08:25 AM

Subject:

Re: [imi] Clarifications to the spec to discuss for our call on Thursday





Better, thanks Mike.

For auditing mode cards do we want to say that the IP/STS SHOULD use the certificate chain to produce the PPID with a cryptographically non-invertible function, such as the one used to calculate the PPID for p-cards.

If we are going to have the spec say that the selector should send the PPID for auditing mode cards, I don't want to infer that using that even with a hash function is better than calculating it from the site cert chain.

=jbradley
On 7-Jan-09, at 11:52 PM, Mike Jones wrote:


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]