PKIX and verification depth.
Cantor, Scott
cantor.2 at osu.edu
Wed Jul 2 10:26:44 EDT 2014
On 7/2/14, 10:23 AM, "Rod Widdowson" <rdw at steadingsoftware.com> wrote:
>> > However that seems like it might be a pretty dangerous change to make
>for
>> > people who are not configuring via the V2 legacy trust engines.
>>
>> I don't see the danger; don't you end up with a default of 1 either way?
>
>Yup, but what I don't know enough to know is whether that is a sensible
>enough default in non-IdP situations to break the current paradigm of
>requiring an (application defined) value.
Aside from not remember whether 0 or 1 means "only one hop", defaulting to
a single step in the chain is basically the best default.
-- Scott
More information about the dev
mailing list