ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] Deployment Scenario 7: Cryptographic Upgrade and Downgrade Attacks

2007-02-28 17:37:53
> The problem is that UNLESS you have the ability to tell people that
> your signing practices are transitional the policy language will be
> insufficiently expressive to provide any value.

Seems to me signers will just sign with both algorithms for a period of time. Regardless of what is expressed in policy, that can't help the sender know the level of deployment of a new verifier capable of handling the new algorithm.

Arvel


_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html