Victor Duchovni wrote:
> So with Kerberos the word hasW its narrower "named security entity"
> technical meaning. With X.509 one tends to talk of "subjects", "issuers",
> "registration authorities", "certification authorities", ... and the word
> "principal" is less common.

part of this has been that x.509 has layered certification authorities,
digital certificates and other business processes on top of any direct
interaction between parties. as a result, the focus of x.509 related
descriptions tends to focus on the certification processes and the
acceptance of those certification processes by relying parties.
(along with any digital certificate representation of those
certification processes)

credentials, certificates, licenses, diplomas, letters of
credit/introduction and other mechanisms have served the world for
centuries ... providing information to relying parties, where the
relying parties didn't have the information themselves and/or have
direct mechanisms for obtaining the information.

digital certificates has been electronic analog of those centuries old
constructs for representation of information for use by relying parties
(where the relying parties have no direct access to the information
and/or other mechanisms for obtaining the information).

the only definition for principal comes from sc27:

    An entity whose identity can be authenticated. [SC27]

doesn't include a definition for principal.

