Skip to content

charter: explicit non-collusion requirement suggested by Dennis - #132

Merged
bwesterb merged 2 commits into
mainfrom
dennis1
Aug 25, 2025
Merged

charter: explicit non-collusion requirement suggested by Dennis#132
bwesterb merged 2 commits into
mainfrom
dennis1

Conversation

@bwesterb

Copy link
Copy Markdown
Collaborator

Comment thread charter-ietf-plants.md Outdated
Realistically, Web PKIs are likely going to continue be evaluated by both Web Clients(TM) and long, long tail of web-adjacent clients of increasing distance to The Web(TM).

Of course, as with today, there is some point at which, on a per-application basis, the application will decide it's better off using a PKI tailored to its needs than one tailored for the Web's needs. But I think it's pretty likely that, like today, there will be some clients that overlap in PKI but don't care to manage a second set of trusted parties to get transparency guarantees. (I also would like more of the long tail to enforce transparency, but there's no escaping the fact that more trusted parties => more overhead to manage them.)

MTC accommodates this, and it's really not hard to accommodate this: allow clients to be configured with just the CA cosigner, and no additional cosigner requirement. But that means MTC doesn't ensure this property, because it allows such clients. It just makes it possible to ensure this property.

Co-authored-by: David Benjamin <davidben@google.com>
@bwesterb
bwesterb merged commit 42ef635 into main Aug 25, 2025
2 checks passed
@davidben
davidben deleted the dennis1 branch August 25, 2025 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants