Redundant signature algorithm info in certs.
"Erik Andersen" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
The question about apparently redundant signature algorithm information in public-key certificates, attribute certificates and CRLs has been raised before. It seems clear that by including the signature algorithm within the body of the cert, it is protected by the signature. But why does the algorithm then has to be part of the signature itself? I am not suggesting to change current specifications. The question could be relevant for new signed structures developed by other specifications. Erik _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix