[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: comments on "shrinkwrap"



-----BEGIN PGP SIGNED MESSAGE-----

At 12:26 AM 8/27/97 +0300, Markku-Juhani Saarinen wrote:
>o it looks like this protocol is for "reduction servers", systems
>  that will do chain reduction for the client. Why can't the client
>  do it itself ? Or is the server supposed to sign the result cert ? 
>  (the draft doesn't say anything about signing)

see my immediately previous message to the list.

>o How can the client be sure that the result cert is actually the
>  true reduced cert ? Reduction can be done in a number of ways
>  that are effectively the same but look different.

Can you give an example of this?  AFAIAK, any CRC in which a given issuer
empowers my final subject key with a given tag is OK, no matter what
reduction was used.

 - Carl

-----BEGIN PGP SIGNATURE-----
Version: PGP for Personal Privacy 5.0
Charset: noconv

iQCVAwUBNAZPg1QXJENzYr45AQGP4wP+PX+XSmpqjeJCTGo4NDlYLWyhAR1w9qRa
+6GVnsAhmdWXlxeHWtO5kv7gPv12zIlFl1NTtKZEJ/d2mvT0WPUikoc22EfBN4Oz
YJH6W/imPk5nYdmJnOO5ZBUk6o4Xe11ypk1E7wepTtGMZz/mIgcC0yH+YSCdfvJa
z5nrA9lwfyo=
=9lLy
-----END PGP SIGNATURE-----


+------------------------------------------------------------------+
|Carl M. Ellison  cme@cybercash.com   http://www.clark.net/pub/cme |
|CyberCash, Inc.                      http://www.cybercash.com/    |
|207 Grindall Street   PGP 2.6.2: 61E2DE7FCB9D7984E9C8048BA63221A2 |
|Baltimore MD 21230-4103  T:(410) 727-4288  F:(410)727-4293        |
+------------------------------------------------------------------+


References: