pem-dev
[Top] [All Lists]

Re: Residential CAs and DN subordination

1993-09-21 11:34:00

I would therefore suggest that the correct form should be something
like 

C=US, O=GTE [or USPS, or RSA DSI, or California DMV],
OU=Residential Person CA [or OU=Customer],
State=California, localityName=Burbank, streetAddress=12345 El Camino,
CN=Johnny Carson


A DN is to uniquely identify the user.  It should not require the CA's name in 
the users' DN.
Just think about how the DN can be specified later?  Do you want to know or 
care what CA I registered with?
Actulally, I think having the CA name in the DN is a source of global 
incompatibility and non-uniqueness.

_______________________________________________________________________
Alireza Bahreman                          E-Mail: 
bahreman(_at_)bellcore(_dot_)com
Bellcore, Room RRC-1K221                  Phone : +1 908 699 7398
444 Hoes Lane, Piscataway, NJ 08854       Fax   : +1 908 336 2943 

<Prev in Thread] Current Thread [Next in Thread>