pem-dev
[Top] [All Lists]

Re: MD Algorithm for v3 Certificates

1995-07-25 08:34:00
On Fri, 21 Jul 1995, Robert W. Shirey wrote:
At 5:28 PM 7/20/95, Donald E. Eastlake 3rd wrote:
If you are going to change to MD5, why not really fix it and dump the
ghastly Dinstinguished Names, the Assinine One syntax, and the other
ISO nonsense.  Can anyone name any successful system that uses
Distinguished Names?  I can think of only one, Lotus Notes, and that
is presumably because it completely hides them and not user ever has
to deal withone.

Of course.  In well-designed X.400 UAs, no user should have to "deal with"
DNs.  Users normally should only have to deal with short, familiar, and
even locally-defined aliases and nicknames, and should seldom even have to

"seldom"?  That just doen't hack it.  If the users never, Never,
NEVER, have to ever see or understand in any way whatsoever a DN, as
in Lotus Notes, then maybe you are getting somewhere.

Personal nicknames are a problem for interchange, not a solution.  You
need to be able to hand names to other persons in the same
organization, but organization wide nicknames don't work either
because you have to sometimes hand them to people beyond your
organization, put them in email that could be forwarded, etc.  And it
doesn't help much to be able to invisibly foward the DN with the
nickname as the nickname may conflict with others at the destination.

You need globally unique and resonably compact names.  RFC822 names
fit the bill very nicely.  They are certainly more mnemonic than
telephone numbers.  And they avoid being the privacy-violating huge
piles of data the DNs are forced to become in their strenuous effort
to assemble perfect globabl uniqueness out of existing non-unique
data.

type those, selecting them from menus instead.  In cases when the full
details of DNs are important for the user to see, they can be displayed in
a familiar, user-friendly format, such as the one used as for the
destination address on a envelope you mail through the postal service.  An
example is the display format in TechMail PEM.

Donald
=====================================================================
Donald E. Eastlake 3rd     +1 508-287-4877(tel)     dee(_at_)cybercash(_dot_)com
   318 Acton Street        +1 508-371-7148(fax)     
dee(_at_)world(_dot_)std(_dot_)com
Carlisle, MA 01741 USA     +1 703-620-4200(main office, Reston, VA)

<Prev in Thread] Current Thread [Next in Thread>