Re: [TLS] [certid] review of draft-saintandre-tls-server-id-check-09

2010-10-06 Thread Peter Saint-Andre
Double sorry, I meant to sent this only to the cer...@ietf.org list: https://www.ietf.org/mailman/listinfo/certid On 10/6/10 2:53 PM, Peter Saint-Andre wrote: > Sorry about the delayed reply, still catching up on list traffic here... > > On 9/22/10 4:11 PM, Henry B. Hotz wrote: >> >> On Sep 22,

Re: [certid] review of draft-saintandre-tls-server-id-check-09

2010-10-06 Thread Peter Saint-Andre
Sorry about the delayed reply, still catching up on list traffic here... On 9/22/10 4:11 PM, Henry B. Hotz wrote: > > On Sep 22, 2010, at 10:09 AM, Peter Saint-Andre wrote: > >> 2. A human user has explicitly agreed to trust a service that >> provides mappings of source domains to target domai

Re: [TLS] [certid] review of draft-saintandre-tls-server-id-check-09

2010-09-23 Thread Martin Rex
Marsh Ray wrote: > > Martin Rex wrote: > > > > Thinking about it, I feel slightly uneasy about some redirects, such as > > https://gmail.com -> 301 -> https://mail.google.com/mail > > > > I think these should never go without a warning. > > That bugs me too. Lots of sites do it though, usuall

Re: [TLS] [certid] review of draft-saintandre-tls-server-id-check-09

2010-09-23 Thread Marsh Ray
On 09/22/2010 08:48 PM, Martin Rex wrote: Henry B. Hotz wrote: [...] For example the user may trust a dedicated discovery service or identity service that securely redirects requests from the source to a target domain. Thinking about it, I feel slightly uneasy about some redirects, such as ht

Re: [certid] review of draft-saintandre-tls-server-id-check-09

2010-09-23 Thread Henry B. Hotz
On Sep 22, 2010, at 10:09 AM, Peter Saint-Andre wrote: > 2. A human user has explicitly agreed to trust a service that > provides mappings of source domains to target domains, such as a > dedicated discovery service or an identity service that securely > redirects requests fr

Re: [certid] review of draft-saintandre-tls-server-id-check-09

2010-09-22 Thread Martin Rex
Henry B. Hotz wrote: > > [...] For example the user may trust a dedicated discovery service > or identity service that securely redirects requests from the source > to a target domain. Thinking about it, I feel slightly uneasy about some redirects, such as https://gmail.com -> 301 -> https://

Re: [certid] review of draft-saintandre-tls-server-id-check-09

2010-09-14 Thread Sean Turner
I'd offered to review this version during the TLS session at IETF 78, but I think I'm going to wait for the next version ;) spt Wes Hardaker wrote: I've reviewed draft-saintandre-tls-server-id-check-09 and find it a good document and support it's forward progress. I do have a few comments tho

Re: [certid] review of draft-saintandre-tls-server-id-check-09

2010-09-14 Thread Peter Saint-Andre
On 9/14/10 10:07 AM, Sean Turner wrote: > I'd offered to review this version during the TLS session at IETF 78, > but I think I'm going to wait for the next version ;) Yes, the authors will work to submit a revised I-D soon, based on all the feedback received so far. Peter -- Peter Saint-Andre h