FYI from relevant WGLC discussion of draft-ietf-xmpp-3920bis...

-------- Original Message --------
Subject: Re: [xmpp] #73: client caching of server certificates
Date: Mon, 21 Jun 2010 20:41:16 -0600
From: Peter Saint-Andre <[email protected]>
To: [email protected]

On 6/21/10 8:37 PM, xmpp issue tracker wrote:
> #73: client caching of server certificates
> --------------------------------+-------------------------------------------
>  Reporter:  stpe...@…           |       Owner:  stpe...@…         
>      Type:  defect              |      Status:  new               
>  Priority:  minor               |   Milestone:                    
> Component:  3920bis             |     Version:                    
>  Severity:  In WG Last Call     |    Keywords:                    
> --------------------------------+-------------------------------------------
>  Section 13.7.2.1.1 states in part:
> 
>  > ... if a user permanently accepts a certificate in this
>  > way, the client MUST cache the certificate (or some
>  > non-forgeable representation such as a hash value) and
>  > in future connection attempts behave as in Sub-Case #3.
> 
>  Ben Campbell commented: "Should we require a mechanism to allow users to
>  revoke trust for such caches certs?"

Probably, although I think that's more properly a matter to be addressed
in draft-saintandre-tls-server-id-check.

Peter

-- 
Peter Saint-Andre
https://stpeter.im/



_______________________________________________
xmpp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/xmpp

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
certid mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/certid

Reply via email to