At 12:37 PM -0400 5/6/08, Turner, Sean P. wrote:
Just a thought ... since we've now got a way to indicate + and - with
requirements should we apply it the key sizes in 3850bis? That way people
will have a hint that in the next update the shorter keys will likely become
not so welcome and large keys more so?
0 < key size < 511 : MUST NOT
512 < key size < 1023 : SHOULD-
1024 < key size < 2048 : MUST
2049 < key size < 4096 : MAY
Beyond what Russ just pointed out, I find the first line to be in bad
taste. Any IETF spec that says "you must not be able to verify a
signature even though it is valid" is pretty offensive.
Can we return to talking about interoperability?