ISSUE-169: Section 5.5.3 creates a burden on browsers to remember past certificates

ISSUE-169: Section 5.5.3 creates a burden on browsers to remember past certificates

http://www.w3.org/2006/WSC/track/issues/

Raised by: Sunil Agrawal
On product: 

As I understand it, this section creates an inescapable obligation on user agents to store certificate history.  Aside from the challenge that no major browser currently does this (as far as I know), this creates privacy and implementation concerns around data retention.  We don't say how long this information must be kept, but we say the browser MUST treat it as a change of security level, which does not seem to leave open the possibility of not storing it.

Received on Monday, 7 January 2008 14:53:31 UTC