simpleSSO
Klingenstein, Nate
nklingenstein at calstate.edu
Thu Dec 22 16:52:31 EST 2016
Rainer,
I think I understand the gist of your arguments, but I don't think I understand the deeper content, and I certainly don't understand the latter parts of your metadata model. I'll need time to think about it..
In your language, I would want the CA to broker "who" trust by adding metadata URL's to certificates. This who is the information regarding where entities live, with DNS/IP not failing in tandem representing a combined security measure.
The CA doesn't have to endorse any information there; it just has to add the URL. You still check "what" with an attesting entity independently.
If you think CA's would be totally unwilling to cut this kind of certificate, then there are multiple ugly fallback options, and any would start to undercut the simple elegance of the model.
Take care,
Nate.
More information about the users
mailing list