Re: Disclosure Signature (dratf-03 to 04)
"Marcus Leech" <[email protected]> Mon, 21 Apr 2003 11:10:41 -0400
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Nortel Networks |
| Message-ID | <[email protected]> |
kai wrote: > > Hello. > > If so, generator is required to use same algorithm as CA, > then if CA takes SHA-512 generator must use same one. > > That means generator cannot take different security level with CA (no choice). > > And also, generator must get it's own certificate from CA, and keep it. > > Regards, > The thinking was that the signature algorithm could be inferred from the certificate, as a way of saving bits in the trace packets. On thinking about it, it's probably a bad idea, and the signature algorithm components should probably be put back into the traced packet. We need to find a suitable registry, or create one, to describe both the hash and signature algorithms. -- ---------------------------------------------------------------------- Marcus Leech Mail: Dept 8M70, MS 012, FITZ Advisor Phone: (ESN) 393-9145 +1 613 763 9145 Security Architecture and Planning Fax: (ESN) 393-9435 +1 613 763 9435 Nortel Networks [email protected] -----------------Expressed opinions are my own, not my employer's------