Problems Not Addressed by Most PKIs
Problems Not Addressed by Most PKIs
- simple ACL is not enough: the need for complex policies
- delegation: user want to defer trust to a third party
- voting: view this page if 2 out of 4 parties say OK
- processing of certificate content
- when the hash algorithm is unknown: policy control
- different types of certificates (X.509, SDSI, PolicyMaker, …)
- the need to provide semantics in a certificate
- what does the signature of this object mean?