Thomson, Martin wrote:
> Why is an identity mismatch any more forgivable than an unknown CA?

The user might have knowledge about DNS aliases but not about the public key
of the unknown CA.

Not sure whether that should all be part of this BCP document though...

Ciao, Michael.
_______________________________________________
certid mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/certid

Reply via email to