>    If the connection to the preferred URI fails, or the fetched CA
>    certificate public key does not match the TAL public key, the RP
>    SHOULD fetch the CA certificate from the next URI, according to the
>    local preference ranking.

in the case of a key mismatch, there would be significant benefit of
reporting it.  but to whom and how?  

randy

_______________________________________________
sidr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/sidr

Reply via email to