[Trans] running code (was: Re: Draft agenda)

Stephen Farrell <stephen.farrell@cs.tcd.ie> Wed, 26 February 2014 12:43 UTC

Date: Wed, 26 Feb 2014 12:43:34 +0000
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: "trans@ietf.org" <trans@ietf.org>, Melinda Shore <melinda.shore@gmail.com>, Phillip Hallam-Baker <hallam@gmail.com>, Eran Messeri <eranm@google.com>
Subject: [Trans] running code (was: Re: Draft agenda)
I'm not that keen on the phrase ritual compliance.

There is a lot of PKI code in the world that assumes
that issuer/serial is a unique identifier for a good
X.509 certificate.

It'd be best to not break such code by invalidating
that assumption.

If there's a good enough reason to do it, that might
be ok, but I figure the burden to demonstrate that
that is in fact ok should be on those arguing for such
a change.


PS: No hats, just a comment:-)