ietf-openpgp
[Top] [All Lists]

Re: Critical bits and notations

2005-05-20 01:47:20

Werner Koch wrote:
On Thu, 19 May 2005 21:43:34 +0100, Ben Laurie said:


This whole discussion scares me. You have an extension mechanism with
no registry for extensions.


We do have a way to register extensions ([5.2.3.16. Notation Data]):

   The IETF name space is registered with IANA. These names MUST NOT
   contain the "@" character (0x40) is this is a tag for the user name
   space.

   Names in the user name space consist of a UTF-8 string tag followed
   by "@" followed by a DNS domain name. Note that the tag MUST NOT
   contain an "@" character. For example, the "sample" tag used by
   Example Corporation could be "sample(_at_)example(_dot_)com".

   Names in a user space are owned and controlled by the owners of that
   domain. Obviously, it's of bad form to create a new name in a DNS
   space that you don't own.

Where do you see the problem?

Doh! The problem lies between my chair and keyboard. Sorry.

A passing comment, though - if you want domain names to be a safe extension mechanism, you should include a date, since they can change hands (without consent of the current owner, even).

Cheers,

Ben.

--
http://www.apache-ssl.org/ben.html       http://www.thebunker.net/

"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff