[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Sip] Signing P-Asserted-Identity



On 7/14/08 11:24 AM, Dean Willis wrote:

On Jul 13, 2008, at 1:05 PM, Hadriel Kaplan wrote:



-----Original Message-----
From: Dean Willis [mailto:dean.willis at softarmor.com]

no, but garden.eden.com could  could sign an identity header with a
From: of adam at nostrum.com.

Not according to 4474.  The cert domain and From domain must match.


But that part COULD be changed, if one adequately described other acceptance rules. One could potentially also "compound @" so we have an @nostrum defined in the context of @eden. Something like a signed uunet route.

Of you could express it cryptographically. Well-Known-Root signs @eden; @eden signs @nostrum. Recipient can examine the cert and determine whether they trust the chain.

/a
_______________________________________________
Sip mailing list  https://www.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use sip-implementors at cs.columbia.edu for questions on current sip
Use sipping at ietf.org for new developments on the application of sip