Once more, LJ valid_to timespan.

Carl Howells chowells at janrain.com
Tue Jul 5 15:39:36 PDT 2005

Paul Crowley wrote:
> I completely agree with everything you say here!  Thanks for putting it 
> so eloquently - I've got a barely-started draft message on the subject 
> saved because I couldn't work out how to express it.

Well, I seem to have not made much progress convincing anyone of 
anything.  As you're the cryptographic expert in the group, I think it 
falls on you to provide cryptographic reasons for one interpretation 
over the other...

I feel kind of like I'm flogging a dead horse on this subject, but there 
should be some kind of spec clarification at the minimum here.  What 
precisely does the valid_to parameter mean?  How should servers choose 
it?  How should consumers use it?   What are the hard requirements, and 
what are the "it would be nice" recommendations?

There just isn't enough information in the spec at the moment.


