RE: [TLS] extension number conflict
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [TLS] extension number conflict



mike-list at pobox.com wrote:
> 
> I agree.  I had to disable the code that implements this feature
> since there is no way to access it.  This makes it difficult to
> test, especially between differing implementations.
> 
> For a feature that will obviously be approved, shouldn't there
> be a way to assign it a number sooner than RFC publication?

I think it is *not* obvious that this feature will be exactly 
the same (that is, interoperable with the -02 draft) in the final 
TLS 1.2 RFC. For example, in addition to the hash algorithm, we
might want to signal support for different signature algorithms 
(e.g. there are at least three standardized ways of doing RSA 
signatures, but the current specs sort of assume that everyone
uses only PKCS#1 1.5, ignoring the PSS and ANSI variants).

(But perhaps allocating one extension number for "private use"
might make sense... )

Best regards,
Pasi

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.