Re: [TLS] TLS 1.2 hash agility
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] TLS 1.2 hash agility



There is only one place where it's needed: CertificateRequest.
That is true at the moment, but if a future addition to the protocol
also requires a signature, you will need to send the list twice.

Or simply make the change then.

I see two options:

  1) use a server extension to advertise signature algorithm support

  2) modify the format of CertificateRequest now, and possibly
     have to change it back later and implement choice 1 anyway

I would choose option 1.

Mike

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.