Blake,
In the spirit of "being liberal in what you accept" and
interoperability, I think some language is needed. How about "receiving
agents SHOULD NOT reorder the SET OF according to DER"?
I respectfully disagree for the reasons that I stated before. There is no
reason why the receiving agent should not be able to decode the signedData
and re-DER-encode the authenticatedAttributes. Your proposed text strongly
discourages that behavior.
================================
John Pawling, jsp(_at_)jgvandyke(_dot_)com
J.G. Van Dyke & Associates, Inc.
www.jgvandyke.com
================================