← Prev in month ← Prev in thread
Next in thread → Next in month →

Re: [xri] Trust model profiles decision (was RE: subject sets (alsosort of: Agenda for August 6, 2009 call))

From
Nat Sakimura <>
Date
2009-08-10T01:35:42+00:00
ID
Thread
Re: [xri] Trust model profiles decision (was RE: subject sets (alsosort of: Agenda for August 6, 2009 call))
So it sounds like where this is ending up, to crib Scott's closing comments
below, is, "...we should define a very minimal set of things around trust
for now, and then leave the rest to profiles."

If I understand Scott correctly, he's saying the XRD 1.0 spec should not
itself define a specific trust model, but define the elements likely to be
needed by various trust models (XRD:Subject, XRD:Link:Subject, signatures,
etc.), and then leave the specifics to trust profiles.

After all the discussion we've had, that approach sounds right to me,
because I'd prefer XRD 1.0 to be as simple and stable as possible, and then
let trust profiles evolve as needed, rather than to try to bind them into
XRD 1.0 (or even 1.x).

I'm also expecting that the TC would define a conventional certificate-based
trust profile, and that the XRI Resolution 3.0 team could define its own
trust profile (which I'm suspecting may be a superset of cert-based trust
profile, but I'm not sure yet).

In any case, I'm comfortable with this approach.

Now for the bad news: due to circumstances beyond my control, I'm tied up
during the day for two more weeks, and will not be able to attend the
telecons either this week (8/13) or next week (8/20). It's not that I don't
want to (though it is August ;-), but I just don't have any other choice.

However I can continue to participate via email at night. So I'll try to
keep moving things along there.

To that end, I'd ask everyone reading this thread to respond +1 (yes), 0
(not sure), or -1 (No) to the following question:

        Do we have consensus that XRD 1.0 should define the XML elements
likely to be necessary for a variety of trust models, plus any processing
rules for those elements that should be universal to all trust models, but
that it should stop there and say that the requirements of any specific
trust model SHOULD be specified by a profile?

=Drummond
← Prev in month ← Prev in thread
Next in thread → Next in month →