ISSUE-169
Section 5.5.3 creates a burden on browsers to remember past certificates
- State:
 - CLOSED
 - Product:
 - wsc-xit
 - Raised by:
 - Johnathan Nightingale
 - Opened on:
 - 2008-01-07
 - Description:
 - As I understand it, this section creates an inescapable obligation on user agents to store certificate history. Aside from the challenge that no major browser currently does this (as far as I know), this creates privacy and implementation concerns around data retention. We don't say how long this information must be kept, but we say the browser MUST treat it as a change of security level, which does not seem to leave open the possibility of not storing it.
 - Related Actions Items:
 ACTION-438 on Thomas Roessler to Draft alternate text around requiring saved SSL state - due 2008-05-20, closed- Related emails:
 - ACTION-452: Update to section 5.4.1 (was 5.5.1) (from tlr@w3.org on 2008-06-06)
 - Meeting record: 2008-05-14 (from tlr@w3.org on 2008-06-06)
 - Meeting record: 2008-05-13 (from tlr@w3.org on 2008-06-06)
 - ACTION-438: saved TLS state and pinning (from tlr@w3.org on 2008-05-14)
 - Re: ISSUE-183, ISSUE-169 (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-14)
 - WSC WG f2f May 2008 Agenda (v 1.1) (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
 - Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from stephen.farrell@cs.tcd.ie on 2008-05-09)
 - Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
 - Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from tlr@w3.org on 2008-05-09)
 - Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from johnath@mozilla.com on 2008-05-09)
 - Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from tlr@w3.org on 2008-05-09)
 - ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
 - Re: Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from hahnt@us.ibm.com on 2008-01-23)
 - RE: Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from dan.schutzer@fstc.org on 2008-01-23)
 - Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-01-22)
 - Re: ISSUE-169: Section 5.5.3 creates a burden on browsers to remember past certificates (from johnath@mozilla.com on 2008-01-07)
 - ISSUE-169: Section 5.5.3 creates a burden on browsers to remember past certificates (from sysbot+tracker@w3.org on 2008-01-07)
 
Related notes:
Raised by Johnathan, not Sunil.
Johnathan Nightingale, 7 Jan 2008, 15:09:55Display change log