On Jun 22, 2005, at 8:38 PM, Peter Gutmann wrote:
So I'd support -256 SHOULD, -384 and -512
MAY.
What about 224 and 513 and 637... ;)
So I think that there's a few aspects to this:
* Create / determine reference for a specification that explains the
SHA > 1 algorithms.
* Create / determine reference for a specification that explains the
use of those digest algorithms in a signature context (that is,
combined with an asymmetric algorithm of some sort).
* Create a profile for CMS that binds algorithm identifiers to
signature algorithms.
* Update MSG spec with a SHOULD / MUST / whatever for the final
algorithms.
Is there something to be done for the CERT profile also?
Blake
--
Blake Ramsdell | Sendmail, Inc. | http://www.sendmail.com