What about this?

Key store – an application’s collection of keys and certificates that may also 
identify the purposes for which they may be used, including the root 
certificate and associated public key that the application may use as a trust 
anchor.

Key store governance policy – the policy adopted by a key store manager that 
sets forth rules governing the key store, including requirements for root CAs 
and subordinate components and entities, such as keys, certificates, 
subordinate CAs, and registration  authorities.

Root CA – a CA with a self-signed certificate and whose public key is included 
as a trust anchor in a key store.

-----Original Message-----
From: Chris Palmer [mailto:[email protected]] 
Sent: Thursday, October 03, 2013 12:03 PM
To: Benjamin T. Wilson
Cc: Bruce Morton; Iñigo Barreira; Karen O'Donoghue; [email protected]
Subject: Re: [wpkops] ID on Trust model

On Thu, Oct 3, 2013 at 9:45 AM, Ben Wilson <[email protected]> wrote:

> Definition of  Root store – I think it should say, “a set of root 
> certificates embedded in a certificate-using client that anchors the 
> certificate chains of end entity certificates.”  (This definition cold 
> go on to explain this further, but I’m assuming that taking the 
> minimalist approach in the definitions is better because it raises 
> less room for debate about whether a particular implementation falls 
> within the definition.)

I think it's better to say "trust anchor store" and "trust anchor"
instead of, specifically, "root". (Throughout.)

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
wpkops mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/wpkops

Reply via email to