Re: [certid] Please explicitly disallow unvetted info in subject names
"Moudrick M. Dadashov" <md@ssc.lt> Thu, 10 June 2010 22:46 UTC
Return-Path: <md@ssc.lt>
X-Original-To: certid@core3.amsl.com
Delivered-To: certid@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
with ESMTP id 41DAD3A67AC for <certid@core3.amsl.com>;
Thu, 10 Jun 2010 15:46:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.001
X-Spam-Level:
X-Spam-Status: No,
score=0.001 tagged_above=-999 required=5 tests=[BAYES_50=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0p1BwKBdMY+f for
<certid@core3.amsl.com>; Thu, 10 Jun 2010 15:46:41 -0700 (PDT)
Received: from mail.ssc.lt (mail.ssc.lt [212.122.83.205]) by core3.amsl.com
(Postfix) with ESMTP id A77FA3A6813 for <certid@ietf.org>;
Thu, 10 Jun 2010 15:46:41 -0700 (PDT)
Received: from localhost ([127.0.0.1] helo=mail.ssc.lt) by mail.ssc.lt with
esmtp (Exim 4.50) id 1OMqW6-0005BQ-B6; Fri, 11 Jun 2010 01:46:30 +0300
Received: from 84.240.23.130 (SquirrelMail authenticated user md@ssc.lt) by
mail.ssc.lt with HTTP; Fri, 11 Jun 2010 01:46:30 +0300 (EEST)
Message-ID: <65182.84.240.23.130.1276209990.squirrel@mail.ssc.lt>
In-Reply-To: <201006101434.o5AEY4NX011362@fs4113.wdf.sap.corp>
References: <4C0E826B.3050904@bolyard.me> from "Nelson B Bolyard" at Jun 8,
10 10:48:27 am <201006101434.o5AEY4NX011362@fs4113.wdf.sap.corp>
Date: Fri, 11 Jun 2010 01:46:30 +0300 (EEST)
From: "Moudrick M. Dadashov" <md@ssc.lt>
To: mrex@sap.com
User-Agent: SquirrelMail/1.4.6
MIME-Version: 1.0
Content-Type: text/plain;charset=utf-8
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal
Cc: certid@ietf.org
Subject: Re: [certid] Please explicitly disallow unvetted info in subject names
X-BeenThere: certid@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: md@ssc.lt
List-Id: Representation and verification of identity in certificates
<certid.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/certid>,
<mailto:certid-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/certid>
List-Post: <mailto:certid@ietf.org>
List-Help: <mailto:certid-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/certid>,
<mailto:certid-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Jun 2010 22:46:44 -0000
> CAs vouch and are liable for every single bit in the ToBeSigned part > of a certificate, no matter what stupid things they claim in any weird > and ineffective "certificate practice statement" (CPS). > > A CA that doesn't is not a CA, but instead a hackers foot in your door. > > This applies equally to all components of the subject DName, and > all X.509v3 extensions, such as all subjectAltNames, all keyUsages, > all extendedKeyUsages, all BasicConstraints, AIA, CRL distribution points, > and whatever else there is. > I agree with the list above except keyUsage and extendedKeyUsage which are somewhat identity neutral. > Blindly copying without validation any data from the PKCS#10 request > into the certificate that they sign would be simply irresponsible and > an act of gross negligence. 100% agree. M.D. cell: +370-699-26662 > > > -Martin > > > > > > > > > > _______________________________________________ > certid mailing list > certid@ietf.org > https://www.ietf.org/mailman/listinfo/certid >
- [certid] Please explicitly disallow unvetted info… Nelson B Bolyard
- Re: [certid] Please explicitly disallow unvetted … Paul Hoffman
- Re: [certid] Please explicitly disallow unvetted … Sean Turner
- Re: [certid] Please explicitly disallow unvetted … Martin Rex
- Re: [certid] Please explicitly disallow unvetted … Nelson B Bolyard
- Re: [certid] Please explicitly disallow unvetted … Bruno Harbulot
- Re: [certid] Please explicitly disallow unvetted … Martin Rex
- Re: [certid] Please explicitly disallow unvetted … Scott Cantor
- Re: [certid] Please explicitly disallow unvetted … Nelson B Bolyard
- Re: [certid] Please explicitly disallow unvetted … Moudrick M. Dadashov
- Re: [certid] Please explicitly disallow unvetted … Peter Saint-Andre