Re: Coding Of Public Signature Algorithm Identifier
"Marcus Leech" <[email protected]> Wed, 15 Jan 2003 12:00:01 -0500
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Nortel Networks |
| Message-ID | <[email protected]> |
Jim Duncan wrote: > > Please add my name to the vote against using OIDs. I've taken a lot of > heat for my opinion on ASN.1 parsers, but I'll continue to say that the > complexity (and the concomitant risk to security) far outweighs any > perceived benefits. In general, use XML. In this case, perhaps a new > registry is the best way to go. > > My two cents' worth. > > Jim It looks like a couple of bytes and a new registry is what we need. I'm thinking "suites" here, with a given byte value representing a "signature suite". RSA_SHA1: 0x00 RSA_MD5: 0x01 DSA_SHA1: 0x03 -- ---------------------------------------------------------------------- Marcus Leech Mail: Dept 8M70, MS 012, FITZ Advisor Phone: (ESN) 393-9145 +1 613 763 9145 Security Architecture and Planning Fax: (ESN) 393-9435 +1 613 763 9435 Nortel Networks [email protected] -----------------Expressed opinions are my own, not my employer's------