[All Lists] [By Thread] [By Date] [Previous] [Next]


From: R. Halevi
Subject: Certificate format
Date: 7 Cheshvan 5782


I confess I do not fully understand either format. But I notice a pattern.

X.509 carries the full weight of hierarchical PKI. Every certificate implies a chain, a root, a validation path. Even when we do not use these features, they are present. The format assumes a world we have rejected.

JWT carries only what is written. A signed claim. Nothing more.

This reminds me of something.

—Dov Halevi


Thread:

[Previous] [Next]


DEP Discussion Archives
https://dep-specs.org/