Re: [Acme] Before entering WGLC ...

2017-06-20 Thread Salz, Rich
> This might be easier to read, though is actually slightly longer: > Where a CAA property has an "account-uri" parameter, a CA MUST NOT > consider that property to authorize issuance in the context of a given > certificate issuance request unless the CA recognises the URI > specified as

Re: [Acme] Before entering WGLC ...

2017-06-20 Thread Hugo Landau
> A CA MAY proceed with issuance if a CAA record is present whose value matches > the account-uri parameter of the account making the request. > If no CAA records have such a match, then the CA MUST NOT proceed with > issuance. This neglects to include the other criteria for validation of a CAA

Re: [Acme] Before entering WGLC ...

2017-06-19 Thread Salz, Rich
How about this: A CA MAY proceed with issuance if a CAA record is present whose value matches the account-uri parameter of the account making the request. If no CAA records have such a match, then the CA MUST NOT proceed with issuance. ___ Acme

Re: [Acme] Before entering WGLC ...

2017-06-19 Thread Hugo Landau
> Like Russ, I find the statement very difficult to read. Would > inverting it be better? > > > A CA MUST NOT issue authorize issuance if a CAA record is present unless > > the "account-uri" parameter identifies the account making a certificate > > issuance request. See previous reply.

Re: [Acme] Before entering WGLC ...

2017-06-18 Thread Martin Thomson
Like Russ, I find the statement very difficult to read. Would inverting it be better? > A CA MUST NOT issue authorize issuance if a CAA record is present unless the > "account-uri" parameter identifies the account making a certificate issuance > request. On 19 June 2017 at 00:16, Salz, Rich

Re: [Acme] Before entering WGLC ...

2017-06-18 Thread Salz, Rich
Thank you. For me, it addresses the issue. Russ, are you ok? ___ Acme mailing list Acme@ietf.org https://www.ietf.org/mailman/listinfo/acme

Re: [Acme] Before entering WGLC ...

2017-06-17 Thread Salz, Rich
> >    . . .  A CA MUST only consider a property with an "account-uri" > >    parameter to authorize issuance where the URI specified is an URI > >    that the CA recognises as identifying the account making a > >    certificate issuance request. > > > > > This is not a [crisp] MUST statement.  I

Re: [Acme] Before entering WGLC ...

2017-06-17 Thread Hugo Landau
> Hugo, the CAA document is in WGLC. Russ raised the following issue on some > text in section 2: > >    . . .  A CA MUST only consider a property with an "account-uri" >    parameter to authorize issuance where the URI specified is an URI >    that the CA recognises as identifying the account

[Acme] Before entering WGLC ...

2017-06-16 Thread Salz, Rich
Hugo, the CAA document is in WGLC. Russ raised the following issue on some text in section 2:    . . .  A CA MUST only consider a property with an "account-uri"    parameter to authorize issuance where the URI specified is an URI    that the CA recognises as identifying the account making a