In reviewing the algorithm draft (draft-ietf-pkix-ipki-pkalgs-01.txt) again, I remembered that I did have one problem with the draft. I think that it is fine that the certificate structure draft does not contain algorithm information. However I feel that the algorithms draft needs to have some MUST style statements contained in it. I propose adding the following text: To fully comply with this document, implementations MUST support DSA Signature (section 2.2.2). Implementations MAY support MD2 RSA signatures for validation but MUST NOT create new certificates using this algorithm. Implementations MAY support all other algorithms in this document at their discretion. jim schaad