The argument you are making is that certificates, not DNs, have a binding to the real world: when you look at a certificate, you can determine (perhaps recursively) the identity of the certifying authority in the real world. You can then ask them to tell you the identity of the subject DN in the real world. The point here is that the Directory, per se, has none of these bindings. /mtr
<Prev in Thread] | Current Thread | [Next in Thread> |
---|---|---|
|
Previous by Date: | Re: Linking authorizations to the DN, jueneman%wotan |
---|---|
Next by Date: | Re: Registration word games, Marshall Rose |
Previous by Thread: | Re: The relationship between an entry and a real-world object, Peter Williams |
Next by Thread: | Re: The relationship between an entry and a real-world object, Peter Williams |
Indexes: | [Date] [Thread] [Top] [All Lists] |