Re: [urn] URI Scheme with Complex Equality Rules

Peter Saint-Andre <stpeter@stpeter.im> Mon, 29 August 2022 17:40 UTC

Return-Path: <stpeter@stpeter.im>
X-Original-To: urn@ietfa.amsl.com
Delivered-To: urn@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DDF70C180A88 for <urn@ietfa.amsl.com>; Mon, 29 Aug 2022 10:40:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.108
X-Spam-Level:
X-Spam-Status: No, score=-7.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=stpeter.im header.b=dBsDrRFj; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=km7BVkvW
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9Y_0f9Gir9h8 for <urn@ietfa.amsl.com>; Mon, 29 Aug 2022 10:40:16 -0700 (PDT)
Received: from wout5-smtp.messagingengine.com (wout5-smtp.messagingengine.com [64.147.123.21]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 67B32C180A8C for <urn@ietf.org>; Mon, 29 Aug 2022 10:40:16 -0700 (PDT)
Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.west.internal (Postfix) with ESMTP id 743693200941; Mon, 29 Aug 2022 13:40:15 -0400 (EDT)
Received: from mailfrontend1 ([10.202.2.162]) by compute5.internal (MEProxy); Mon, 29 Aug 2022 13:40:15 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=stpeter.im; h=cc :content-transfer-encoding:content-type:date:date:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:sender:subject:subject:to:to; s=fm2; t=1661794814; x= 1661881214; bh=vxpiiAkr2OK84aVY4vMaCTYftnZ6ArYZ+9+2ETumArI=; b=d BsDrRFjxG25IMVk5+eMNFjrKEH+mPfSdRutBevNcR/GoYaf8MwIciww2nyhA4YDA xH2G6BrRVmyCbQjsAH7JsoGcvZQDCSrhffeYnJxCsiiPGGQN43hrUBnn14NO88KM vr8AvlBfPIwG3/dkH3LEeC1PpVxx1Dx2rzaprvratZ3E8WuZc0b6MxOmdNsGm38h +IRkqSP6CpZJlxhAgU5Jdhm2tABFcbWYbxTZddT735VuUuJDOj0WJiR8mhPQL33f DNoNhndtUp8GqELCi9lbUI/WGDvQo/S7uC66gjkEQr4zuUV5HpLNBZR725UDCCR5 CD3+7U+OSvnXQr6J6e55Q==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:date:feedback-id:feedback-id:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:sender :subject:subject:to:to:x-me-proxy:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm1; t=1661794814; x=1661881214; bh=v xpiiAkr2OK84aVY4vMaCTYftnZ6ArYZ+9+2ETumArI=; b=km7BVkvWTv3hkJovO Aja8h9gPVjDhto/kSyVSDnJhsDNzbOBpn/PKpo+uqUvImS7rhb2uXEjhW/UCQtF9 OLJiwy2R/5LtQFw4jrRghQ7KZ9PWR5sZUa2COyacp1SiQwHQX+HQnqvihLnf0d1J lgv+mYiRpu+kJyxrARKjtuH2XbQJ9VD3nMb7Sfpfn5Lqs2hWE2fZ83oNegEy5cgQ Jmp6f3sfvRTlwcwBxU21DnTD+9wBdVA8jzeZ3qrfbf7Cprd+WCAypx2rfxJ8n3cP ovHzscM+esNhzr2OI+Wj20A6djg0z8/WOxq/gBgWSewiGHNqZ482jBS1cX2uS4Wz Mlh4g==
X-ME-Sender: <xms:_vkMY_tJo1qs5RB865Jj2FJYvGsr_TnAMymOxU9cj6efAR__uXAI1A> <xme:_vkMYwceWHFCa2WMkSmdF_V8zj70S4K60xPJ7zdnVxrhdJZQ8jBRLyiSgq4CcwfvI e8obZw7NrL2OUgnaA>
X-ME-Received: <xmr:_vkMYyxrUyV6fD9FdVTdj6dJMaKoY2Fvu2WYHBKfG7VK8rG2kZDQYlULCrrNvKlh>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvfedrvdekuddgudduiecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfgh necuuegrihhlohhuthemuceftddtnecunecujfgurhepkfffgggfuffvfhfhjggtgfesth ejredttdefjeenucfhrhhomheprfgvthgvrhcuufgrihhnthdqtehnughrvgcuoehsthhp vghtvghrsehsthhpvghtvghrrdhimheqnecuggftrfgrthhtvghrnhepvdevtdeuffeive elgeegueehieeiuedvfedtuedtuddvieehgeehkeehuddtheeunecuffhomhgrihhnpehi vghtfhdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfh hrohhmpehsthhpvghtvghrsehsthhpvghtvghrrdhimh
X-ME-Proxy: <xmx:_vkMY-OVQRB7j_y7ayWIMV_7DowZlacLVigYSw1MoKaug5zkM-GhbQ> <xmx:_vkMY_-HHhxGqs7hr-mVbcysu-pYfG-QVyDJ_XeeFJr4pgFG_9n3fg> <xmx:_vkMY-WdKWmW9793-j05i_MeUnoMXdZ6spHe6hSnKb1IpyijbnUWow> <xmx:_vkMY8FB-phGWcevri6yPxLcrorytAyiBLIfhCCRtRx3yVLjV6H6DA>
Feedback-ID: i24394279:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 29 Aug 2022 13:40:14 -0400 (EDT)
Message-ID: <301f2fcd-b932-f5fd-5f0b-5c9d2c56147e@stpeter.im>
Date: Mon, 29 Aug 2022 11:40:13 -0600
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:91.0) Gecko/20100101 Thunderbird/91.12.0
Content-Language: en-US
To: urn@ietf.org
References: <SJ0PR08MB8288507205BE2CD811F5D19BFA759@SJ0PR08MB8288.namprd08.prod.outlook.com> <CA+9kkMBbeHRn+pQEO4v90d0ifCaxEZW7FU2QRUtgD8oiuD0JKg@mail.gmail.com> <SJ0PR08MB82881C9645C9F215BBB5CB03FA759@SJ0PR08MB8288.namprd08.prod.outlook.com>
From: Peter Saint-Andre <stpeter@stpeter.im>
In-Reply-To: <SJ0PR08MB82881C9645C9F215BBB5CB03FA759@SJ0PR08MB8288.namprd08.prod.outlook.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/urn/4x9-B3CIz2CC7LXcs_x6WO35uBg>
Subject: Re: [urn] URI Scheme with Complex Equality Rules
X-BeenThere: urn@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Revisions to URN RFCs <urn.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/urn>, <mailto:urn-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/urn/>
List-Post: <mailto:urn@ietf.org>
List-Help: <mailto:urn-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/urn>, <mailto:urn-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Aug 2022 17:40:21 -0000

One further small point...

On 8/26/22 8:18 AM, Randy Armstrong (OPC) wrote:

> The identifiers are used in the subjectAltName of X509 Certificates and 
> uniquely identify the application that the Certificate is assigned to.

This is another reason to use a URI scheme, since you can re-use the 
URI-ID matching rules from RFC 6125 (a specification that's in the 
latter stages of being revised, see [1]).

Peter

[1] https://datatracker.ietf.org/doc/draft-ietf-uta-rfc6125bis/