Re: [pkix] Self-issued certificates

"Miller, Timothy J." <tmiller@mitre.org> Thu, 16 July 2015 16:16 UTC

Return-Path: <tmiller@mitre.org>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D20781A9238 for <pkix@ietfa.amsl.com>; Thu, 16 Jul 2015 09:16:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level:
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id obqnMveKwK5m for <pkix@ietfa.amsl.com>; Thu, 16 Jul 2015 09:16:54 -0700 (PDT)
Received: from smtpvmsrv1.mitre.org (smtpvmsrv1.mitre.org [192.52.194.136]) by ietfa.amsl.com (Postfix) with ESMTP id 41EAE1A9147 for <pkix@ietf.org>; Thu, 16 Jul 2015 09:16:54 -0700 (PDT)
Received: from smtpvmsrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id DC41B6C0706; Thu, 16 Jul 2015 12:16:53 -0400 (EDT)
Received: from imshyb01.MITRE.ORG (imshyb01.mitre.org [129.83.29.2]) by smtpvmsrv1.mitre.org (Postfix) with ESMTP id CF2936C06DA; Thu, 16 Jul 2015 12:16:53 -0400 (EDT)
Received: from imshyb02.MITRE.ORG (129.83.29.3) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1044.25; Thu, 16 Jul 2015 12:16:54 -0400
Received: from na01-bl2-obe.outbound.protection.outlook.com (10.140.19.249) by imshyb02.MITRE.ORG (129.83.29.3) with Microsoft SMTP Server (TLS) id 15.0.1044.25 via Frontend Transport; Thu, 16 Jul 2015 12:16:54 -0400
Received: from BY2PR09MB109.namprd09.prod.outlook.com (10.242.36.149) by BY2PR09MB111.namprd09.prod.outlook.com (10.242.36.19) with Microsoft SMTP Server (TLS) id 15.1.213.14; Thu, 16 Jul 2015 16:16:52 +0000
Received: from BY2PR09MB109.namprd09.prod.outlook.com ([10.242.36.149]) by BY2PR09MB109.namprd09.prod.outlook.com ([10.242.36.149]) with mapi id 15.01.0213.000; Thu, 16 Jul 2015 16:16:52 +0000
From: "Miller, Timothy J." <tmiller@mitre.org>
To: "mrex@sap.com" <mrex@sap.com>
Thread-Topic: [pkix] Self-issued certificates
Thread-Index: AQHQvO6Win+gscY4xki0Ne4yM5Okv53YpJmAgADHUoCAAC03gIABiFsAgABHlACAAXDtAIAAB9uAgAFHIYCAAAi2AIAAESSAgAAI8gA=
Date: Thu, 16 Jul 2015 16:16:52 +0000
Message-ID: <74A5D249-85E1-4887-ADD1-C6084F07B265@mitre.org>
References: <20150716154449.B20051A1EC@ld9781.wdf.sap.corp>
In-Reply-To: <20150716154449.B20051A1EC@ld9781.wdf.sap.corp>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: sap.com; dkim=none (message not signed) header.d=none;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [128.29.115.169]
x-microsoft-exchange-diagnostics: 1; BY2PR09MB111; 5:YeFbqhUloLoGZ9DN9cv9ukV9A+dBnShz2Ww1AXj6F9StDfnBD46pnqx8HSXLLvH9Mk6Mqn/mKQVilUQ93y9Fm1OIYqcvtLYz+EiHr8zpuBg2D5cOZWyWUYrpUEV5FP8Xz1R/XTlsT+cVvW+DSY+iWg==; 24:jD8hG87fD8sqgDTSl+SWoCXZ1Fzj267Mq53IcTdYpFFFpTCuFcp8CEdC/6tjrrXpQUfvMElaUQDaTs5CY8DURqFhBQ9xMvxqsEDhgkxXzyM=; 20:aVnW1uWq5CsNEGNkjo1F/gi8/K2sDq0LV77ztnSDhy9V2etru3Cbk2Q0N3vy+oS/ZDcWTjjEXUmWr8azcOy01g==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BY2PR09MB111;
by2pr09mb111: X-MS-Exchange-Organization-RulesExecuted
x-microsoft-antispam-prvs: <BY2PR09MB111CF9796F522C534531799AE990@BY2PR09MB111.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(5005006)(3002001); SRVR:BY2PR09MB111; BCL:0; PCL:0; RULEID:; SRVR:BY2PR09MB111;
x-forefront-prvs: 0639027A9E
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(102836002)(5001960100002)(2351001)(77096005)(106116001)(92566002)(66066001)(33656002)(99286002)(2950100001)(2900100001)(36756003)(54356999)(76176999)(122556002)(189998001)(110136002)(50986999)(83716003)(40100003)(46102003)(62966003)(87936001)(2501003)(2656002)(77156002)(82746002)(5002640100001)(86362001)(7059030)(104396002); DIR:OUT; SFP:1101; SCL:1; SRVR:BY2PR09MB111; H:BY2PR09MB109.namprd09.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
Content-Type: text/plain; charset="utf-8"
Content-ID: <DD267E53DCD59845A9594F42CA304B9A@namprd09.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Jul 2015 16:16:52.0583 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c620dc48-1d50-4952-8b39-df4d54d74d82
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY2PR09MB111
X-OriginatorOrg: mitre.org
Archived-At: <http://mailarchive.ietf.org/arch/msg/pkix/P9br6nKTghN6ZxlWQF0YxHgx2so>
Cc: PKIX <pkix@ietf.org>
Subject: Re: [pkix] Self-issued certificates
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Jul 2015 16:16:56 -0000

> I had not recognized your term "RFC 4210 rollover announcement" as
> something that refers to a technical protocol that includes
> the relevant PDUs.
> 
> rfc4210 is sufficient complex and awkward that is not used anywhere
> around TLS (at least the stuff that I come in contact with) nor common
> web-service or pkcs#7/CMS based data exchange scenarios.

I didn’t say it was *used*, I said it would *work*.  ;)

— T