pem-dev
[Top] [All Lists]

Re: Embedded secure URLs

1995-10-04 08:47:00
On Wed, 4 Oct 1995 Jueneman(_at_)gte(_dot_)com wrote:

On Mon, 2 Oct 1995 Jueneman(_at_)gte(_dot_)com wrote:

(I'd really prefer an X.500 solution, where instead of a URL there would be
a
distinguished name of the document. That way, when someone decides to take
down one file server and move all of the document somewhere else, users
wouldn't be left with a bunch of useless, dangling URLs. But I'm not
holding
my breath.)

I can't conceive of why you think that Distinguished Names would be more
stable than Domain Names, which I assume is what prompted the above.

I should have put my remarks in a double set of parentheses, to avoid jerking
everyone's chain. But just to rise to the bait, assuming that a document is
given a reasonable name, perhaps c=US, o=Certificates R Us,
cAPolicyUrl=http:// ... I see no reason for the document name, and hence the
DN, to ever have to change. The URL can then be changed as required to point
to the current location of the document. Am I missing something obvious? 

Names of documents, whether DN's or UNICODE strings, need never change.
Of course, unless you throw in a serial number or a name registration 
system or the like, they won't be unique.  But a name is of no use in
getting the document unless you can map it to some actual storage, at
least at the time you want to do the retrieval.  So how do you store,
maintain, access this mapping?  As long as you have a good mapping system,
it hardly matters why the original name is but as long as it is going
to ultimately resolve to something like a URL its just seems parsimoneous
to start with someting like a domain name or URL.

(PS: What if the country in the C= disappears?  Well, you could leave
the name the same.  What if a brand new country appears and adopts the
same name?  Does it have to honor all the old names from the old version
of that country names?  What if some of the records are lost?  What if
there are two existing countries simultaneously with the same name 
(happens all the time with governments in exile and even with recoginized
countries there are currently two with *excatly* the same flag).  Do you
add a serial number to the country name?  What authority issues such 
serial numbers and what if the new sovereign country with the same name
just insists on using 1 anyway, since they don't want to admit to being
second?
        And all this is just for countries!  What happens when Certificates
R Us goes bankrupt, loses its records, and another company is formed with
the same name, etc., etc., etc.,
        Someday people will face the fact the the DN dream of constructing
stable unique names for any amount of existing used name like stuff was 
always doomed to failure.  Add enough stuff to be reasonable sure they are
unique and they are unstable and unusably long.  Make them short enough 
to be moderately stable and usable and they won't be unique.
        The only ways to have unique searchable names are within the scope of
a single authority (can deleteage hierarchially) which either issues its own
unique names, like serial numbers, or registers names and rejects any which
are duplicates (like corporate name registrations). I suppose such an
authority can exist for DNs but it seems better developed for domain names
and they are much more useful in the real world.)

BTW, I agree that with prudent planning, it should be possible to create a
Domain Name that is used to indicate the always stable name for a file server
that would contain such information. My experience is that people tend to load
up such servers with lots of different files, all under the common, stable
name, and then suddenly the files won't fit anymore and some people have to
change the name of the file server, leaving previously valid URLs invalid.

It's not that the problem can't be solved, e.g., with linked URLs. It's just
that most of the time it _isn't_ addressed until it is too late. Human nature,
I suppose.

I can certainly agree with that.

Bob

Robert R. Jueneman
GTE Laboratories
1-617-466-2820 Office
1-508-264-0485 Telecommuting

Donald
=====================================================================
Donald E. Eastlake 3rd     +1 508-287-4877(tel)     dee(_at_)cybercash(_dot_)com
   318 Acton Street        +1 508-371-7148(fax)     
dee(_at_)world(_dot_)std(_dot_)com
Carlisle, MA 01741 USA     +1 703-620-4200(main office, Reston, VA)

<Prev in Thread] Current Thread [Next in Thread>