shibboleth-dev - RE: client certificate chains and 1.3 IdP
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: "'Ian Young'" <>
- Cc: "'Walter Hoehn'" <>, <>
- Subject: RE: client certificate chains and 1.3 IdP
- Date: Wed, 6 Jul 2005 12:43:06 -0400
- Organization: The Ohio State University
> That's very concise; thanks.
Concise but really annoying. Bugs on top of bugs, and nobody willing to fix
anything.
> Some commercial CAs have really exciting signing chains, though, and
> several federations already accept certificates from some such CAs.
> SwissSign (SWITCH use them) and GlobalSign (at least SDSS, Athens and
> InQueue use them) are examples known to me. So this boat has sailed,
> whether chaining seems sensible or not (and I'm not expressing an
> opinion on that).
Yeah, I know the reasoning, but I'm not really sure people understand the
implications of using those kinds of certificates. The deeper the chain, the
more likely it is that there are no controls on name clashes across the
hierarchy.
This will obviously go in the wiki regardless.
-- Scott
- RE: client certificate chains and 1.3 IdP, (continued)
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/05/2005
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/05/2005
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/05/2005
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/06/2005
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/06/2005
- Re: client certificate chains and 1.3 IdP, Ian Young, 07/06/2005
- Re: client certificate chains and 1.3 IdP, Walter Hoehn, 07/06/2005
- Re: client certificate chains and 1.3 IdP, Ian Young, 07/06/2005
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/06/2005
- Re: client certificate chains and 1.3 IdP, Ian Young, 07/06/2005
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/06/2005
- RE: client certificate chains and 1.3 IdP, Thomas Lenggenhager, 07/07/2005
- Re: client certificate chains and 1.3 IdP, Ian Young, 07/06/2005
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/06/2005
- Re: client certificate chains and 1.3 IdP, Ian Young, 07/06/2005
- RE: client certificate chains and 1.3 IdP, Scott Cantor, 07/06/2005
- Re: client certificate chains and 1.3 IdP, Walter Hoehn, 07/06/2005
Archive powered by MHonArc 2.6.16.