IETF-SSH archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: Nits in current drafts
Sam Hartman <hartmans-ietf%mit.edu@localhost> writes:
>However doing new design work seems inappropriate at this stage in the
>process.
I'd agree with that, but this isn't really new design work, it's just dropping
an ambiguous/underspecified format. In other words leave the cert/key section
exactly as is, and just remove the underspecified signature format. So I
think this meets the "drop the feature" requirement, all that's being dropped
is the use of the "xyz-pgp" signature format, leaving the "xyz-pgp" key/cert
format in place.
(Stepping back a bit, I think the problem here has always been the tying of
each non-SSH key/cert format to a corresponding non-SSH signature format,
even though there's no good reason for this and the non-SSH sig format is
often under-specified. Unifying all the signatures into a single format
that's already universally used and widely field-tested doesn't seem like a
major showstopper).
Peter.
Home |
Main Index |
Thread Index |
Old Index