J. Postel's scientific contributions

Citations

... One possible improvement to the security of the Web PKI system is simply to adopt and deploy the certificate path constraints already defined in X.509 and PKIX, most notably, the name constraint, discussed in subsection 8.3.3. This would allow restriction of the name space for certificates issued by a given CA, e.g., based on the DNS top-level domain country codes (TLDcc), as defined in RFC 1591 [264]. For example, a Canadian CA may be restricted to the TLDcc for Canada (.ca). ...