[All Lists] [By Thread] [By Date] [Previous] [Next]
From: R. Halevi
Subject: Certificate format
Date: 7 Cheshvan 5782
I confess I do not fully understand either format. But I notice a pattern.
X.509 carries the full weight of hierarchical PKI. Every certificate implies a chain, a root, a validation path. Even when we do not use these features, they are present. The format assumes a world we have rejected.
JWT carries only what is written. A signed claim. Nothing more.
This reminds me of something.
—Dov Halevi
Thread: