Another forward from ongoing XMPP discussion...

/psa

-------- Original Message --------
Subject: Re: [xmpp] #74: user acceptance of non-matching presented
identities
Date: Mon, 21 Jun 2010 20:42:07 -0600
From: Peter Saint-Andre <[email protected]>
To: [email protected]

On 6/21/10 8:40 PM, xmpp issue tracker wrote:
> #74: user acceptance of non-matching presented identities
> --------------------------------+-------------------------------------------
>  Reporter:  stpe...@…           |       Owner:  stpe...@…         
>      Type:  defect              |      Status:  new               
>  Priority:  minor               |   Milestone:                    
> Component:  3920bis             |     Version:                    
>  Severity:  In WG Last Call     |    Keywords:                    
> --------------------------------+-------------------------------------------
>  Section 13.7.2.1.1 states in part:
> 
>  > Sub-Case #3:  The server's certificate includes no presented
>  > identity that matches the reference identity to which the
>  > entity attempted to connect but a human user has permanently
>  > accepted the certificate during a previous connection attempt;
> 
>  Ben Campbell commented: "This needs to be associated with the identity the
>  use was trying to reach when she accepted the cert in the first place,
>  right? That is, if some other server offers the same cert, it's not
>  automatically accepted, right?"

Correct. This should be covered in draft-saintandre-tls-server-id-check
(but I don't think it is currently, so I'll forward this message to the
[email protected] list).

Peter

-- 
Peter Saint-Andre
https://stpeter.im/



_______________________________________________
xmpp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/xmpp

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
certid mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/certid

Reply via email to