{"type":"rich","version":"1.0","author_name":"npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd","author_url":"https://nostr.ae/npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2012-11-27\n📝 Original message:Luke-Jr - common subset of what operating systems ship is fine for me\nas long as people do due diligence around mobile OS' here. It seems\neasier to me to just grab a list from a popular browser, on the\ngrounds that SSL is mostly used by them so nobody is going to buy an\nSSL cert rejected by IE/Firefox/Chrome/etc. But intersecting OS lists\nis effectively the same.\n\nFor my own clients I'd just ship my own copy of the canonical CA certs\nregardless, because integrating with each operating systems\nproprietary crypto APIs is a lot of work vs just loading a pem file\ninto OpenSSL. If there are a lot of people who want to use the OS cert\nmanagement UIs then I guess that can be a point wallet clients compete\non.\n\n\u003e Removing that and adding a opaque string called domain name, or\n\u003e identityName would be sufficient to move the conversation forward\n\u003e without the x.509 baggage.\n\nBut it would result in implementations that do not meet the requirements.\n\nYes, X.509 has problems. It's in the proposal because we can get the\neffect we want (verifiable domain names in the UI) in about 50 lines\nof code, today, with the id-verified keys people actually have already\nbought.\n\nAs Gavin says, we can add optional fields later to extend the protocol\nin a backwards compatible way."}
