RE: Logotypes in certificates

"David Cross" <dcross@microsoft.com> Sat, 17 March 2001 21:34 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id QAA09608 for <pkix-archive@odin.ietf.org>; Sat, 17 Mar 2001 16:34:52 -0500 (EST)
Received: from localhost by above.proper.com (8.9.3/8.9.3) with SMTP id NAA20368; Sat, 17 Mar 2001 13:34:15 -0800 (PST)
Received: by mail.imc.org (bulk_mailer v1.12); Sat, 17 Mar 2001 13:34:03 -0800
Received: from mail2.microsoft.com (mail2.microsoft.com [131.107.3.124]) by above.proper.com (8.9.3/8.9.3) with SMTP id NAA20306 for <ietf-pkix@imc.org>; Sat, 17 Mar 2001 13:34:02 -0800 (PST)
Received: from 157.54.9.101 by mail2.microsoft.com (InterScan E-Mail VirusWall NT); Sat, 17 Mar 2001 13:11:42 -0800 (Pacific Standard Time)
Received: from red-msg-02.redmond.corp.microsoft.com ([157.54.12.70]) by inet-imc-01.redmond.corp.microsoft.com with Microsoft SMTPSVC(5.0.2195.2883); Sat, 17 Mar 2001 13:11:42 -0800
x-mimeole: Produced By Microsoft Exchange V6.0.4418.65
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Subject: RE: Logotypes in certificates
Date: Sat, 17 Mar 2001 13:11:42 -0800
Message-ID: <24A715275661C8428C00432EFCA5CB7C01E3E9D8@red-msg-02.redmond.corp.microsoft.com>
Thread-Topic: Logotypes in certificates
Thread-Index: AcCuj/fuECSLKsJcRF6ps/9vKlsONgAlt4Xg
From: David Cross <dcross@microsoft.com>
To: Michael Zolotarev <michael.zolotarev@baltimore.com>, ietf-pkix@imc.org
X-OriginalArrivalTime: 17 Mar 2001 21:11:42.0803 (UTC) FILETIME=[DD9CC230:01C0AF26]
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id NAA20307
Precedence: bulk
List-Archive: http://www.imc.org/ietf-pkix/mail-archive/
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: mailto:ietf-pkix-request@imc.org?body=unsubscribe
Content-Transfer-Encoding: 8bit

Sounds like a reasonable suggestion.  Still, I would not want this in
son-of-RFC2459.

David B. Cross

 



-----Original Message-----
From: Michael Zolotarev [mailto:michael.zolotarev@baltimore.com] 
Sent: Friday, March 16, 2001 7:09 PM
To: David Cross; Stefan Santesson; ietf-pkix@imc.org
Subject: RE: Logotypes in certificates


Probably a better alternative to including a logotype into a certificate
would be to include a reference to a [signed] logotype. As an extension,
containing a uri of a logotype which is stored somewhere. The drawback
is that it requires the verifier to be connected, obviously. But
certificate verification normally assumes that you are connected. The
size of a logotype won't matter much.

Naturally, a logotype should be signed by the same entity which issued
the certificate which contains the reference to the logotype. it also
allows flexible update of logotype if necessary, should a change be made
within validity period of the certificate (i.e. a new photo required
because I've grown a bead).

Michael