#56: "*" domain labels MUST NOT be redacted

 I can't think of any legitimate reason to redact a "*" label.

 We should disallow redaction of "*" labels, so that a bad actor cannot
 attempt to hide their use of "*" labels in a disallowed context (e.g. EV
 certs).

 6962-bis needs to state this as a CA requirement.

-- 
-------------------------------------+-------------------------------------
 Reporter:                           |      Owner:  draft-ietf-trans-
  [email protected]           |  [email protected]
     Type:  defect                   |     Status:  new
 Priority:  major                    |  Milestone:
Component:  rfc6962-bis              |    Version:
 Severity:  -                        |   Keywords:
-------------------------------------+-------------------------------------

Ticket URL: <http://trac.tools.ietf.org/wg/trans/trac/ticket/56>
trans <http://tools.ietf.org/trans/>

_______________________________________________
Trans mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/trans

Reply via email to