CERTDIST Comments

Russ Housley <housley@spyrus.com> Wed, 02 June 1999 00:40 UTC

Received: from mail.proper.com (mail.proper.com [206.86.127.224]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id UAA08126 for <smime-archive@odin.ietf.org>; Tue, 1 Jun 1999 20:40:21 -0400 (EDT)
Received: (from majordomo@localhost) by mail.proper.com (8.8.8/8.8.5) id QAA26220 for ietf-smime-bks; Tue, 1 Jun 1999 16:28:46 -0700 (PDT)
Received: from spyrus.com (mail.spyrus.com [207.212.34.30]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id QAA26216 for <ietf-smime@imc.org>; Tue, 1 Jun 1999 16:28:45 -0700 (PDT)
Received: from rhousley_laptop.spyrus.com (swf-caw1.spyrus.com [207.212.34.211]) by spyrus.com (8.7.6/8.7.3/arc) with SMTP id QAA01411; Tue, 1 Jun 1999 16:26:59 -0700 (PDT)
Message-Id: <4.1.19990601103748.009fa720@mail.spyrus.com>
Message-Id: <4.1.19990601103748.009fa720@mail.spyrus.com>
X-Sender: rhousley@mail.spyrus.com (Unverified)
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.1
Date: Tue, 01 Jun 1999 10:44:37 -0400
To: jimsch@EXCHANGE.MICROSOFT.com
From: Russ Housley <housley@spyrus.com>
Subject: CERTDIST Comments
Cc: ietf-smime@imc.org
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="=====================_346546==_"
Sender: owner-ietf-smime@imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Jim:

I have embedded comments in the attached copy of CERTDIST.

After reading and commenting, I wonder if a general signed directory
attribute mechanism would be preferable.  Such a mechanis would allow any
attribute to be signed by the user for posting in his directory entry.  I
am not sure how searches would work in the directory with such an attribute.

The directory entry could contain many attributes:
	sMIMEcapabilities
	emailAddress
	userCertificate
	whateverElse
	signedAttributes
		SIGNED ( sMIMEcapabilities )
		SIGNED ( whateverElse )

Does this generalization make sence?

Russ