RE: Coding Of Public Signature Algorithm Identifier

"Tom-PT Taylor" <[email protected]> Thu, 16 Jan 2003 13:08:45 -0500
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
I submitted an update to the document yesterday.  I'll modify that when it
comes out to conform to this.

> -----Original Message-----
> From: Leech, Marcus [CAR:8M70:EXCH] 
> Sent: Thursday, January 16, 2003 11:54 AM
> To: Mikael Olsson
> Cc: Leech, Marcus [CAR:8M70:EXCH]; Jim Duncan; Taylor, Tom-PT 
> [CAR:5N00:EXCH]; [email protected]
> Subject: Re: Coding Of Public Signature Algorithm Identifier
> 
> 
> Mikael Olsson wrote:
> > 
> > You have my vote on that approach.  The actual suite specification 
> > would obviously have to have more detail than that, specifically:
> >   - What hash output length should we use? SHA1 produces 160 bits,
> >     but there are security benefits in truncating to e.g. 128 bits.
> >   - What is the asymmetric key length? (Or can this simply be
> >     inferred from the downloaded public key?)
> > ... but other than those (implementation) details, I'm all for it.
> > 
> > And on a related topic:
> > Personally, I do not see a convincing reason to make this list any 
> > longer than a single suite initially. (I've already pointed out RSA 
> > encrypted SHA1 as my personal preference.)
> > 
> I think that the asymmetric key length can be inferred.  So, 
> how about we
>   mandate:
> 
>   RSA_SHA1_160 0x00
> 
>   And establish an IANA registry for other values there.
> 
> Tom: would you incorporate this into the document, and see 
> about establishing
>   an IANA registry?
> 
> -- 
> ----------------------------------------------------------------------
> Marcus Leech                             Mail:   Dept 8M70, 
> MS 012, FITZ
> Advisor                                  Phone: (ESN) 
> 393-9145  +1 613 763 9145
> Security Architecture and Planning       Fax:   (ESN) 
> 393-9435  +1 613 763 9435
> Nortel Networks                          [email protected]
> -----------------Expressed opinions are my own, not my 
> employer's------
>