[Webfunds-devel] TOOD_scw

Ian Grigg iang@systemics.com
Tue, 22 Aug 2000 21:29:57 -0400


Questions in TODO_SCW:

      I.b)  PKI  

        * top level [cert] signs [contract] signing key (and itself)

           -- Why not the server key?

           ++ purpose of the top level key is to sign only owned,
              internal keys that present purpose within userIdTag.

              If we wanted a signing of the [operator] key we would
              need to use a key other than the [contract] and [cert].
              The WoT key would possibly work, but for now, as we
              see how this question pans out, I've just stuck the  
              [operator] key in the contract so that it is a context
              indication with no particular statement of meaning.

              (Yes, we need to develop a better way to do this, we
              are overloading the PKI in the contract somewhat.)

Many other changes made to file, now much smaller, being used as
record of future changes, no outstanding msut-fix bugs...

Tanks!
-- 
iang