Using the Subject UID field to identify a certificate (v. the subject/user) will likely break the 1993 X.500 ACL mechanism, which assumes some semantics of the UID, i.e. it distinguishes multiple (serial) reuse of a DN. ACLs identify a user by the <DN/optional UID> combination. I would suggest we take a closer look at X.501/X.511 (93) before going too far in this direction...
<Prev in Thread] | Current Thread | [Next in Thread> |
---|---|---|
|
Previous by Date: | Re: Certificate DNs, CA-Naming, jueneman%wotan |
---|---|
Next by Date: | MD6?, burt |
Previous by Thread: | Re: Certificate DNs, CA-Naming, jueneman%wotan |
Next by Thread: | Re: Certificate DNs, CA-Naming, Francisco Jordan |
Indexes: | [Date] [Thread] [Top] [All Lists] |