Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Discuss the implications of serving certificates from some CA (#16)
From IETF discussion, it seems there is some confusion about the nature of PKI-based authentication, the implications of serving a correct certificate from an untrustworthy CA, and the roles and goals of subscribers and relying parties in this interaction. There also appears to be some concern of actors using this kind of confusion to convince confused root program operators of inadvisable actions, as well as some discussion amplifying this confusion. Spell this out in Security Considerations, in hopes of reducing all this confusion. Also spell out how agility reduces what would otherwise be a strong compatibility vs security conflict. This implication seems to also have been non-obvious to folks.
- Loading branch information