ietf-smtp
[Top] [All Lists]

Re: RFC 3207 STARTTLS

2008-10-26 08:13:57

Willie Gillespie wrote:
Alessandro Vesely wrote:
BTW, why don't we write the IP number on our server certificates?

Because sometimes domains resolve to more than one IP address?

Not if one can issue multiple certificates.

I think people reckon that it doesn't add much so much to security to be worth the hassle. Hostmasters may prefer not tying certificates to IPs, so they are free to change them; thereby implying that certification is not part of ordinary DNS maintenance.

<Prev in Thread] Current Thread [Next in Thread>