Re: Logotypes in certificates

Stefan Santesson <stefan@addtrust.com> Thu, 29 March 2001 14:44 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with SMTP id JAA15998 for <pkix-archive@odin.ietf.org>; Thu, 29 Mar 2001 09:44:24 -0500 (EST)
Received: from localhost by above.proper.com (8.9.3/8.9.3) with SMTP id GAA02479; Thu, 29 Mar 2001 06:43:45 -0800 (PST)
Received: by mail.imc.org (bulk_mailer v1.12); Thu, 29 Mar 2001 06:43:29 -0800
Received: from exafix.addtrust.com ([212.112.175.83]) by above.proper.com (8.9.3/8.9.3) with ESMTP id GAA02422 for <ietf-pkix@imc.org>; Thu, 29 Mar 2001 06:43:28 -0800 (PST)
Received: from santesson.addtrust.com ([192.168.101.117]) by exafix.addtrust.com with Microsoft SMTPSVC(5.0.2195.1600); Thu, 29 Mar 2001 16:42:07 +0200
Message-Id: <5.0.0.25.2.20010329163956.027ffcb8@mail.addtrust.com>
X-Sender: sts@mail.addtrust.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0
Date: Thu, 29 Mar 2001 16:43:32 +0200
To: Dean Povey <povey@dstc.qut.edu.au>, Aram Perez <aram@pacbell.net>
From: Stefan Santesson <stefan@addtrust.com>
Subject: Re: Logotypes in certificates
Cc: ietf-pkix@imc.org
In-Reply-To: <200103231030.f2NAUYm12689@thunder.dstc.qut.edu.au>
References: <Your message of "Thu, 22 Mar 2001 22:05:11 PST." <B6E02797.3BF9%aram@pacbell.net>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-OriginalArrivalTime: 29 Mar 2001 14:42:07.0796 (UTC) FILETIME=[6DFABF40:01C0B85E]
Precedence: bulk
List-Archive: http://www.imc.org/ietf-pkix/mail-archive/
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: mailto:ietf-pkix-request@imc.org?body=unsubscribe

Dean,

At 20:30 2001-03-23 +1000, Dean Povey wrote:
>We also need to think beyond just logos.  What about photographs of employees
>in Certificates?  This is such a useful thing to be able to do.  I am
>cognisant of the reticence of people to stuff too much in certs, and I think
>in general this is a good principle.  But providing it is done sensibly I 
>think
>there is a fair bit to suggest that a scheme like this would significantly
>contribute to the security of PKI systems.

Photographs in certificates are already covered in RFC 3039 (see 
biometricInfo extension).

My original proposal for logos actually used the same technique to include 
logos as is used in RFC 3039 to include photos and other displayable images 
of biometric-characteristics.

/Stefan