I hesitate to remove it.  I agree that since we removed contact-based
recovery, it's less central, but since the "contact" field is still there,
CAs will need to consider the risks if they ever use it.

On Thu, Aug 18, 2016 at 4:53 PM, Jacob Hoffman-Andrews <[email protected]> wrote:

> Here's a PR removing the contact channel from the threat model:
>
> https://github.com/ietf-wg-acme/acme/pull/174
>
> On 08/17/2016 05:07 PM, Jacob Hoffman-Andrews wrote:
> > Our Threat Model section includes a "Contact channel," but with the
> > removal of recovery options, the spec no longer has anything to say
> > about what gets sent to contacts. I think we should probably remove it
> > from the threat model. Any thoughts?
> >
> > _______________________________________________
> > Acme mailing list
> > [email protected]
> > https://www.ietf.org/mailman/listinfo/acme
> >
>
> _______________________________________________
> Acme mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/acme
>
_______________________________________________
Acme mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/acme

Reply via email to