#10: note that end-entity certs can be dristrib'd to http clients ?

 http://www.ietf.org/mail-archive/web/websec/current/msg00306.html


 Subject: Re: [websec] Decouple HSTS's two orthogonal effects?
 From: Adam Barth <[email protected]>
 Date: Tue, 29 Mar 2011 14:35:58 -0700
 To: Tom Ritter <[email protected]>
 Cc: [email protected]

 <snip/>

 > Also Section 9 recommends distributing root CA certs to users'
 > browsers, and does not mention the possibly of distributing the leaf
 > certs instead.  Less related, but I prefer to trust organizations leaf
 > certs individually than their root cert.

 I don't have a problem with also recommending leaf certs, but you
 should check with =JeffH.

 Adam

-- 
-------------------------------------------+--------------------------------
 Reporter:  jeff.hodges@…                  |       Owner:  =JeffH
     Type:  defect                         |      Status:  new   
 Priority:  major                          |   Milestone:        
Component:  strict-transport-sec           |     Version:        
 Severity:  Active WG Document             |    Keywords:        
-------------------------------------------+--------------------------------

Ticket URL: <http://trac.tools.ietf.org/wg/websec/trac/ticket/10>
websec <http://tools.ietf.org/websec/>

_______________________________________________
websec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/websec

Reply via email to