[caops-wg] Certificate Bridging and the Grid Certificate Profile version 0.21

Mike 'Mike' Jones mike.jones at manchester.ac.uk
Tue Mar 27 09:58:03 CDT 2007


Hi folks,

I've just been asked to add an LSU grid certificate to one of our servers. 
We sometimes do things like this as a special case reading the CP/CPS 
where available.  However, that's not the point of this email!

Poking around the web for details of the
"/O=Louisiana State University/OU=CCT/OU=ca.cct.lsu.edu/CN=CCT CA"
Certificate Authority I came across the SURAgrid bridge CA. In their 
documentation they advise _against_ using the Authority Key Identifier 
(for obvious reasons).  The Grid Certificate Profile draft currently
recommends that AKID be used (table in section 2.4).  Might it be 
appropriate for us to add a note that by doing this one essentially 
removes the possibility for joining a bridging scheme such as 
https://www.pki.virginia.edu/nmi-bridge/ ?

Cheers,
Mike
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 1992 bytes
Desc: S/MIME Cryptographic Signature
Url : http://www.ogf.org/pipermail/caops-wg/attachments/20070327/c33134a0/attachment.bin 


More information about the caops-wg mailing list