IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Nits in current drafts



Sam Hartman <hartmans-ietf%mit.edu@localhost> writes:

>However doing new design work seems inappropriate at this stage in the
>process.

I'd agree with that, but this isn't really new design work, it's just dropping
an ambiguous/underspecified format.  In other words leave the cert/key section
exactly as is, and just remove the underspecified signature format.  So I
think this meets the "drop the feature" requirement, all that's being dropped
is the use of the "xyz-pgp" signature format, leaving the "xyz-pgp" key/cert
format in place.

(Stepping back a bit, I think the problem here has always been the tying of
 each non-SSH key/cert format to a corresponding non-SSH signature format,
 even though there's no good reason for this and the non-SSH sig format is
 often under-specified.  Unifying all the signatures into a single format
 that's already universally used and widely field-tested doesn't seem like a
 major showstopper).

Peter.




Home | Main Index | Thread Index | Old Index