ietf-mailsig
[Top] [All Lists]

Re: alternate key server mechanisms

2005-07-27 21:53:18

On July 27, 2005 at 22:52, "Arvel Hathcock" wrote:

How can a policy lookup be avoided with each and every verification if the 
purpose of the policy semantics are to "allow the sender to describe their 
signature policy in sufficient detail that the lack of a signature header 
that
complies with the policy can be understood to indicate a forgery."

How can a verifier know whether a signature "compiles with the policy" 
unless it query for the policy always?

BINGO!

--ewh

<Prev in Thread] Current Thread [Next in Thread>