[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: I-D ACTION:draft-ietf-pkix-time-stamp-07.txt
Michael,
>The same about hash algorithms supported by the TSA for messageImprints -
>the TSA should accept all 'common' types. If it does not understand the
>algorithm's OID, the error will be returned to the client. So that the
>client will have to try a different algorithm. With makes it nothing but
>ugly, making me to believe any static information about TSA's capabilities
>should be communicated separately from the actual TSA responses. The client
>should discover the capabilities of the TSA before transacting, out-of-band
>or from some published TSA practice statement.
>
>Regards
>Michael
However, the problem I see with a published TSA practice statement is that
it would not currently lend itself to automation unless XML was used. This
is why in the first place I had suggested using the S/MIME capabilities
attribute to indicate any static information about TSA's capabilities.
Checking the S/MIME capabilities attribute should not be a major issue for a
requestor since he/she must be able to use S/MIME to verify the integrity of
a TimeStampToken.
Francois
___________________________________
Francois Rousseau
Director of Standards and Conformance
Chrysalis-ITS
1688 Woodward Drive
Ottawa, Ontario, CANADA, K2C 3R7
frousseau@chrysalis-its.com Tel. (613) 723-5077 Ext. 419
http://www.chrysalis-its.com Fax. (613) 723-5078