ISSUE-169
Section 5.5.3 creates a burden on browsers to remember past certificates
- State:
- CLOSED
- Product:
- wsc-xit
- Raised by:
- Johnathan Nightingale
- Opened on:
- 2008-01-07
- Description:
- As I understand it, this section creates an inescapable obligation on user agents to store certificate history. Aside from the challenge that no major browser currently does this (as far as I know), this creates privacy and implementation concerns around data retention. We don't say how long this information must be kept, but we say the browser MUST treat it as a change of security level, which does not seem to leave open the possibility of not storing it.
- Related Actions Items:
ACTION-438 on Thomas Roessler to Draft alternate text around requiring saved SSL state - due 2008-05-20, closed- Related emails:
- ACTION-452: Update to section 5.4.1 (was 5.5.1) (from tlr@w3.org on 2008-06-06)
- Meeting record: 2008-05-14 (from tlr@w3.org on 2008-06-06)
- Meeting record: 2008-05-13 (from tlr@w3.org on 2008-06-06)
- ACTION-438: saved TLS state and pinning (from tlr@w3.org on 2008-05-14)
- Re: ISSUE-183, ISSUE-169 (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-14)
- WSC WG f2f May 2008 Agenda (v 1.1) (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
- Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from stephen.farrell@cs.tcd.ie on 2008-05-09)
- Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
- Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from tlr@w3.org on 2008-05-09)
- Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from johnath@mozilla.com on 2008-05-09)
- Re: ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from tlr@w3.org on 2008-05-09)
- ISSUE-169 Section 5.5.3 creates a burden on browsers to remember past certificates (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-05-09)
- Re: Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from hahnt@us.ibm.com on 2008-01-23)
- RE: Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from dan.schutzer@fstc.org on 2008-01-23)
- Agenda: WSC WG distributed meeting, Wednesday, 2008-01-23 (from Mary_Ellen_Zurko@notesdev.ibm.com on 2008-01-22)
- Re: ISSUE-169: Section 5.5.3 creates a burden on browsers to remember past certificates (from johnath@mozilla.com on 2008-01-07)
- ISSUE-169: Section 5.5.3 creates a burden on browsers to remember past certificates (from sysbot+tracker@w3.org on 2008-01-07)
Related notes:
Raised by Johnathan, not Sunil.
Johnathan Nightingale, 7 Jan 2008, 15:09:55Display change log