ISSUE-169

Section 5.5.3 creates a burden on browsers to remember past certificates

State:
CLOSED
Product:
wsc-xit
Raised by:
Johnathan Nightingale
Opened on:
2008-01-07
Description:
As I understand it, this section creates an inescapable obligation on user agents to store certificate history. Aside from the challenge that no major browser currently does this (as far as I know), this creates privacy and implementation concerns around data retention. We don't say how long this information must be kept, but we say the browser MUST treat it as a change of security level, which does not seem to leave open the possibility of not storing it.
Related Actions Items:
Related emails:
  1. ACTION-452: Update to section 5.4.1 (was 5.5.1) (from tlr@w3.org on 2008-06-06)
  2. Meeting record: 2008-05-14 (from tlr@w3.org on 2008-06-06)
  3. Meeting record: 2008-05-13 (from tlr@w3.org on 2008-06-06)
  4. ACTION-438: saved TLS state and pinning (from tlr@w3.org on 2008-05-14)
  5. Re: ISSUE-183, ISSUE-169 (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-14)
  6. WSC WG f2f May 2008 Agenda (v 1.1) (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
  7. Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from stephen.farrell@cs.tcd.ie on 2008-05-09)
  8. Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
  9. Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from tlr@w3.org on 2008-05-09)
  10. Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from johnath@mozilla.com on 2008-05-09)
  11. Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from tlr@w3.org on 2008-05-09)
  12. ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
  13. Re: Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from hahnt@us.ibm.com on 2008-01-23)
  14. RE: Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from dan.schutzer@fstc.org on 2008-01-23)
  15. Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-01-22)
  16. Re: ISSUE-169: Section 5.5.3 creates a burden on browsers to remember past certificates (from johnath@mozilla.com on 2008-01-07)
  17. ISSUE-169: Section 5.5.3 creates a burden on browsers to remember past certificates (from sysbot+tracker@w3.org on 2008-01-07)

Related notes:

Raised by Johnathan, not Sunil.

Johnathan Nightingale, 7 Jan 2008, 15:09:55

Display change log ATOM feed


Mary Ellen Zurko <mzurko@us.ibm.com>, Chair, Thomas Roessler <tlr@w3.org>, Staff Contact
Tracker (configuration for this group), originally developed by Dean Jackson, is developed and maintained by the Systems Team <w3t-sys@w3.org>.
$Id: 169.html,v 1.1 2010/10/11 09:35:09 dom Exp $