Re: draft-ietf-itrace-03.txt
Mikael Olsson <[email protected]> Sat, 18 Jan 2003 01:49:29 +0100
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
Marcus Leech wrote: > > I've been thinking about the public-key algorithm field in the > key-disclosure > message. It seems to me that if we have a URL in the > public-key-information > message, the "stuff" that the URL points to can contain not only the > public key information, but also algorithms, etc. But that unfortunately also means that the actual config on the host that emits tracebacks and the published info can be out of sync. :/ > The most common case would be that the URL would point to an X.509 > cert, which contains algorithm information already. We perhaps don't > need the algorithm field at all in the ITRACE message. Comments? Maybe that is true for the public key encryption algorithm. (Can't say for sure; my X.509 knowledge is hazy at best.) However, I'm fairly certain that X.509 certs have no info whatsoever about hashing algorithms used to produce signatures. We would at _least_ need to specify that much in the actual itrace packets. -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com