I would imagine that domain owners would simply use the Issuer Name and Serial 
Number combination to match the precert to the actual cert. 

-Rick

-----Original Message-----
From: Gervase Markham [mailto:[email protected]] 
Sent: Tuesday, April 01, 2014 1:29 PM
To: Rob Stradling; Peter Bowen; Rick Andrews
Cc: [email protected]
Subject: Re: [Trans] Angle brackets in the PRIVATE option (Ticket #1)

On 01/04/14 21:26, Rob Stradling wrote:
> Hi Gerv.  I don't think this is desirable.
> 
> Only the domain owner needs to know what the unmasked subdomains are, 
> and they can do this by simply looking at the corresponding Certificate.

Does it not help with your combinatorial explosion, because it's then much 
easier to match up a potential cert with its logged precert?

Or am I mistaken?

Gerv
_______________________________________________
Trans mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/trans

Reply via email to