RE: X.509 Attribute Certificates extensions in PKIX Certificates?

Anders Rundgren <anders.rundgren@jaybis.com> Wed, 17 March 1999 10:39 UTC

Received: from mail.proper.com (mail.proper.com [206.86.127.224]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id FAA28224 for <pkix-archive@odin.ietf.org>; Wed, 17 Mar 1999 05:39:25 -0500 (EST)
Received: (from majordomo@localhost) by mail.proper.com (8.8.8/8.8.5) id AAA21158 for ietf-pkix-bks; Wed, 17 Mar 1999 00:28:10 -0800 (PST)
Received: from smtp.udac.net (smtp.udac.net [193.44.79.123]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id AAA21152 for <ietf-pkix@imc.org>; Wed, 17 Mar 1999 00:28:07 -0800 (PST)
Received: from caesar.udac.se (caesar.udac.se [193.44.79.10]) by smtp.udac.net (8.9.1/8.9.1) with ESMTP id JAA05106 for <ietf-pkix@imc.org>; Wed, 17 Mar 1999 09:34:35 +0100
Received: from HYDRA ([195.67.109.114]) by caesar.udac.se (8.7.3/NetworkC-1) with SMTP id JAA77914; Wed, 17 Mar 1999 09:34:00 +0100
Received: by HYDRA with Microsoft Mail id <01BE7059.5BD30970@HYDRA>; Wed, 17 Mar 1999 09:34:30 +0100
Message-ID: <01BE7059.5BD30970@HYDRA>
From: Anders Rundgren <anders.rundgren@jaybis.com>
To: "ietf-pkix@imc.org" <ietf-pkix@imc.org>, 'Michael Crerar' <mcrerar@dvnet.com>
Subject: RE: X.509 Attribute Certificates extensions in PKIX Certificates?
Date: Wed, 17 Mar 1999 09:34:29 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-pkix@imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit

Michael,
Michael Crerar wrote:
I haven't seen a reaction to this message and I am also interested in
the state of PKIX standards regarding attribute certificates.  Do any of
the current PKIX standards describe the format of an attribute
certificate and the role of the entity issuing attribute certificates? 
Or is the attribute certificate only a concept that has yet to be
formalized?

I think that the closest you can get is this IETF draft:

http://www.ietf.org/internet-drafts/draft-ietf-tls-ac509prof-00.txt

A "slight" problem is how to use attribute certificates and the link below
contains a suggestion that could be applied to practically any PKI:

http://www.mobilephones-tng.com/v100/dynamiccerts.html

I would VERY MUCH APPRECIATE your (entire PKIX-list) comments to this!

Regards
Anders Rundgren
Senior Internet e-commerce Architect
Jaybis AB
+46   70 - 627 74 37
http://www.mobilephones-tng.com