Re: [sidr] GOST & SIDR
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [sidr] GOST & SIDR



On Fri, 17 Apr 2009, Randy Bush wrote:

And is there any reason why algorithm agility won't just work?

how do you capability negotiate with a cert?  i understand how to do it
with a protocol peer, but not a static object.

I'm not suggesting negotiation.

I'm asking "will RPKI partcipants who want to use algorithms different from the norm and/or their parents be able to do so without any bad effects"? Using strange algorithms may well mean that most relying parties can't verify the certificates, but that's to be expected.

i suppose with enough complexity, ...  but this is one of those time i
think there is a version number in the protocol.

So long as "version number" isn't a synonym for "flag day", there's nothing wrong with having one. But we already have algorithm identifiers in the certs. Are those enough?

-- Sam

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.