ietf
[Top] [All Lists]

Re: Multiple roots & E2E PKI trust discovery, chain management & capabilities exchange

2005-07-22 20:57:05
On Sat, 23 Jul 2005, Masataka Ohta wrote:

PKI has nothing to do with E2E.
As CAs and DNS servers are intermediate systems, neither PKI nor
DNS are E2E.
As intermediate systems, they don't have any information on
ongoing transaction that they can't give any real guarantee.

Masataka-San, your NOTASIP ID still rings in my mind after all these years and I see that your approach at providing consistency to a discussion continues to be as thoughtful as it ever has been.

This being said, in my question, I did knowingly imply that PKI as we know it from CAs is not end-to-end as CAs are intermediate systems.

In your opinion, what do you see as the latest state of the art thinking towards PKI that is true-er to an E2E environment, knowing that I am looking for an answer in the context of my need to catch up quick so that I can better defend the need for a multiple roots at the NXX level in the ENUM environment - my true goal being to tell carriers to screw it with Carrier-ENUM. My argument is that you cannot subdomain a telephone number which can remain reachable from a telephone keypad, thus the need for competition at the registry level (if not, innovation will be restricted by the transaction costs of registering entries in Tier1B).

I have described my proposed Tier1C here in details: http://www.crtc.gc.ca/cisc/COMMITTE/C-docs/CNCO0004.doc

If pursuing this discussion gets too wild on IETF-discuss, I will agree to defer the ongoing discussion to the E2E-interest mailing list on postel.org and refer back once I have a better idea how stable is the ground. However, true here is my ambition to frame the discussion in such a way that I can know how to tackle my Tier1C proposed framework into the broader perspective of where the IETF has been, where it can go and where it does not or no longer wants to go (at least in the short term).

-=Francois=-
819 692 1383

_______________________________________________
Ietf mailing list
Ietf(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/ietf