Re: I-D ACTION:draft-ietf-pkix-pi-08.txt
"David P. Kemp" <dpkemp@missi.ncsc.mil> Wed, 12 May 2004 23:10 UTC
Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA18704 for <pkix-archive@lists.ietf.org>; Wed, 12 May 2004 19:10:47 -0400 (EDT)
Received: from above.proper.com (localhost.vpnc.org [127.0.0.1]) by above.proper.com (8.12.11/8.12.9) with ESMTP id i4CMCvuR062651; Wed, 12 May 2004 15:12:57 -0700 (PDT) (envelope-from owner-ietf-pkix@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.11/8.12.9/Submit) id i4CMCvGY062650; Wed, 12 May 2004 15:12:57 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-pkix@mail.imc.org using -f
Received: from stingray.missi.ncsc.mil (stingray.missi.ncsc.mil [144.51.50.20]) by above.proper.com (8.12.11/8.12.9) with ESMTP id i4CMCuVT062643 for <ietf-pkix@imc.org>; Wed, 12 May 2004 15:12:56 -0700 (PDT) (envelope-from DPKemp@missi.ncsc.mil)
Message-ID: <200405122138.i4CLchhk006004@stingray.missi.ncsc.mil>
Date: Wed, 12 May 2004 18:12:04 -0400
From: "David P. Kemp" <dpkemp@missi.ncsc.mil>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: Anders Rundgren <anders.rundgren@telia.com>
CC: ietf-pkix@imc.org
Subject: Re: I-D ACTION:draft-ietf-pkix-pi-08.txt
References: <005701c3e08e$9b392fe0$1400a8c0@augustcellars.local> <00c701c3e121$0ae3af90$0500a8c0@arport> <4017C963.8060600@bull.net> <200405121708.i4CH7dim022214@stingray.missi.ncsc.mil> <001001c43864$e11bb130$0500a8c0@arport>
In-Reply-To: <001001c43864$e11bb130$0500a8c0@arport>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 12 May 2004 22:12:05.0026 (UTC) FILETIME=[28802020:01C4386E]
Sender: owner-ietf-pkix@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit
It is certainly technically possible to put any attribute into the subject name syntax. An unfortunate side effect of an infinitely-flexible syntax is that de-facto standards such as those you cite can arise. DNS (and by extension, email address) is a namespace rooted in the TLDs (.com, .edu, ...). PIs are another namespace rooted either in some CA-specific environment (policy=CA) or in an independent manner (by assigning agency) that allows multiple CAs to issue certificates to one identifiable user. Subject Distinguished Names are intended to be a third namespace, typically rooted by Country. When you say "just stuff an email address in the middle of a DN", that is equivalent to saying "just stuff a DN in the middle of an email address: "dpkemp@missi.(C=US,O=DoD,CN=Dave).ncsc.mil" Fortunately, RFC822 prohibits such foolishness in a way that cannot be circumvented by fools. Unfortunately, X.509 DN syntax does not prohibit anything, and it is up to system architects to establish rules that enable DNs to form a namespace rather than a cloaca for miscellaneous unrelated data. It is as easy for CAs to ignore those rules as it is for Harry Homeowners to ignore electrical codes and wire their basements without grounding and with hot and neutral lines connected randomly. The fact that something can be done and is in fact done millions of times does not make it a good idea. SubjectAltName brings some syntax-enforced discipline to certificate naming. Feel free to ignore it, and even to urge others to ignore it, but at least feel a twinge of shame when you do so. Anders Rundgren wrote: >>It is my hope that PI will become an RFC in the near future, so >>that certificates (from an un-named large PKI :-) that currently >>handle PIs by munging them into Common Name (e.g., >>CN="Kemp.David.P.0514101404") will have a saner alternative. > > > The de-facto standard, already engraved in *millions* of certs is > putting 0514101404 in serialNumber. > > This is almost as de-facto standard as putting e-mail addresses in DNs > which in turn is almost as de-facto standard as using URIs for naming > globally unique objects. > > C:\Internet-Drafts>del draft-ietf-pkix-pi-*.txt > > :-) > > Pardon my complaints, let there be an RFC! But don't expect > this scheme to become the trend. > > There is a slight problem with the whole idea. Either RPs require > and act upon the PI-data or they don't care about it. This in my > opinion makes the extension redundant or is just another way > to screw up validation. > > If you on top of this add policy extensions I believe a real disaster > is in the making. > > Anders >
- I-D ACTION:draft-ietf-pkix-pi-08.txt Internet-Drafts
- RE: I-D ACTION:draft-ietf-pkix-pi-08.txt Jim Schaad
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Anders Rundgren
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Denis Pinkas
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Peter Sylvester
- RE: I-D ACTION:draft-ietf-pkix-pi-08.txt Santosh Chokhani
- RE: I-D ACTION:draft-ietf-pkix-pi-08.txt Jim Schaad
- RE: I-D ACTION:draft-ietf-pkix-pi-08.txt BARARI, TIRTHANKAR
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Denis Pinkas
- RE: I-D ACTION:draft-ietf-pkix-pi-08.txt Santosh Chokhani
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Denis Pinkas
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Denis Pinkas
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Denis Pinkas
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt David P. Kemp
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Anders Rundgren
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt David P. Kemp
- RE: I-D ACTION:draft-ietf-pkix-pi-08.txt Al Arsenault
- RE: I-D ACTION:draft-ietf-pkix-pi-08.txt Peter Gutmann
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Anders Rundgren
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt David P. Kemp
- RE: I-D ACTION:draft-ietf-pkix-pi-08.txt Tom Gindin
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Anders Rundgren
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt David P. Kemp
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Anders Rundgren
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt David P. Kemp
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Peter Gutmann
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Tom Gindin
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt David P. Kemp
- Re: I-D ACTION:draft-ietf-pkix-pi-08.txt Peter Gutmann