Re: draft-ietf-itrace-03.txt

Mikael Olsson <[email protected]> Sat, 18 Jan 2003 01:49:29 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>

Marcus Leech wrote:
> 
> I've been thinking about the public-key algorithm field in the
> key-disclosure
>   message.  It seems to me that if we have a URL in the
> public-key-information
>   message, the "stuff" that the URL points to can contain not only  the
>   public key information, but also algorithms, etc.

But that unfortunately also means that the actual config on the
host that emits tracebacks and the published info can be out
of sync.  :/

> The most common case would be that the URL would point to an X.509
>   cert, which contains algorithm information already.  We perhaps don't
>   need the algorithm field at all in the ITRACE message.  Comments?

Maybe that is true for the public key encryption algorithm.
(Can't say for sure; my X.509 knowledge is hazy at best.)

However, I'm fairly certain that X.509 certs have no info whatsoever
about hashing algorithms used to produce signatures.  We would at
_least_ need to specify that much in the actual itrace packets.


-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com