ACTION-456: validated certificates and their importance

From the minutes [1], ACTION-455 was about adding a brief note to
section 5.1.3 that says that validated certificates are actually
today's garden variety CA-issued cert.  I've therefore added the
following to that section:

>  The notion of a validated certificate in this specification
>  corresponds to the domain validated certificate commonly deployed
>  on the Web. This type of certificate attests to a binding between
>  a domain name registration and a key pair; additional certificate
>  attributes are often not validated.

  -- http://www.w3.org/2006/WSC/drafts/rec/rewrite.html#sec-validated-certificates

The action item for some reason talked about security
considerations.  I wonder whether a more detailed discussion of that
topic is best taken care of in the context of adding a few more
introductory sentences to Yngve's proposed text about EV and DV
certificates; see [2] and ACTION-453.

Maybe worth a few minutes on a conference call.

1. http://lists.w3.org/Archives/Public/public-wsc-wg/2008Jun/0011.html
2. http://lists.w3.org/Archives/Public/public-wsc-wg/2008Jun/0000.html
-- 
Thomas Roessler, W3C  <tlr@w3.org>  +33-4-89063488

Received on Friday, 6 June 2008 17:23:25 UTC