[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Signature format and smart cards



>>>>> "Brian" == Brian Swander <briansw@microsoft.com> writes:

 Brian> Then the solution is to negotiate signature encoding type as
 Brian> well.  Clearly, the best solution is to add signature encoding
 Brian> type to the cert and cert request payload headers.  We cannot
 Brian> do this.  So I again propose to flag the oid-ful format with a
 Brian> 1 in the reserved field of these headers until ipsecond can
 Brian> fix this.

Why can't this wait?

I tend to agree with Micheal that hacking up the protocol at this late 
stage is not desirable.  Given that there are devices that work with
the spec as it stands, why the rush?

	paul


Follow-Ups: References: