Re: [dane] draft-fanf-dane-smtp

2012-05-29 07:10:03
James Cloos <cloos(_at_)jhcloos(_dot_)com> wrote:

I've read the draft now.  It looks good.


§3 specifies that the hostname MUST be in the cert as an DNS-ID and
also MAY be there as a CN-ID.

That is basically adapting what RFC 6125 says to the specifics of SMTP,
i.e. subsetting the possible identities (omitting SRV etc.). Perhaps I
ought to make the DNS-ID a SHOULD rather than MUST to follow RFC 6125
more exactly.

