> Matthew MacKenzie wrote:
>
>> Farrukh Najmi wrote:
>>
>> Good point.
>>
>> SSL based communication between Registry Client and Registry is
>> already specified in section 10.3.1. I assume most
>> registry-to-registry communication *WILL* be over SSL. Does that
>> address the issue?
>
> Technically, yes, but I think we should mention that if
> registry-to-registry communication is via mutually authenticated SSL,
> requests and responses should not be signed.
Also, something like this should be added to authentication section:
"Authentication is (optionally) done through ssl client auth, and if
certificate does not match or is not present, server treats it as
Registry Guest".
Diego
--
Diego Ballve
Digital Artefacts Europe
http://www.digital-artefacts.fi