Re: Disclosure Signature (dratf-03 to 04)

"Marcus Leech" <[email protected]> Mon, 21 Apr 2003 11:10:41 -0400
Newsgroups gmane.ietf.itrace
Organization Nortel Networks
Message-ID <[email protected]>
kai wrote:
> 
> Hello.
> 
> If so, generator is required to use same algorithm as CA,
> then if CA takes SHA-512 generator must use same one.
> 
> That means generator cannot take different security level with CA (no choice).
> 
> And also, generator must get it's own certificate from CA, and keep it.
> 
> Regards,
> 
The thinking was that the signature algorithm could be inferred from the
  certificate, as a way of saving bits in the trace packets.  On thinking about
  it, it's probably a bad idea, and the signature algorithm components should
  probably be put back into the traced packet.  We need to find a suitable
  registry, or create one, to describe both the hash and signature algorithms.



-- 
----------------------------------------------------------------------
Marcus Leech                             Mail:   Dept 8M70, MS 012, FITZ
Advisor                                  Phone: (ESN) 393-9145  +1 613 763 9145
Security Architecture and Planning       Fax:   (ESN) 393-9435  +1 613 763 9435
Nortel Networks                          [email protected]
-----------------Expressed opinions are my own, not my employer's------