Re: Delegated Credentials and the Web PKI

2019-03-08 Thread Ryan Sleevi via dev-security-policy
(Sending from the right e-mail this time) Thanks for the responses! I think this is a great thing to bring here, because there are some interplays with policy and implications that can affect the design, as I discuss below. I'm trying to be mindful of proffering solutions outside of the TLS-WG,

Re: Delegated Credentials and the Web PKI

2019-03-08 Thread Ryan Sleevi via dev-security-policy
On Fri, Mar 8, 2019 at 4:35 PM watson--- via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > We are interested in CAs signing x509 certificates that can be used with > delegated credentials for TLS, > https://tools.ietf.org/html/draft-ietf-tls-subcerts-03. The certificates >

Delegated Credentials and the Web PKI

2019-03-08 Thread watson--- via dev-security-policy
We are interested in CAs signing x509 certificates that can be used with delegated credentials for TLS, https://tools.ietf.org/html/draft-ietf-tls-subcerts-03. The certificates to be signed by the CA are x509 certificates that contain a special extension that identifies them as being able to