Ilari Liusvaara <[email protected]> wrote: >> > > Given that location and content type are already optional, how can you >> > argue that lack of size makes the draft incomplete? >> > >> > Ok, the location being optional, and the size being mandatory does not >> > make sense to me either. size being mandatory when location is >> > supplied would make sense to me >> > >> >> How come x5u doesn't have a length?
> With x5u, one could impose some pretty small size limits. For example,
> certificate chains >1MB should be extremely rare in wild. If the device
> is constrained, one could apply even lower limits.
It could be that x5u ought to have had a length.
It could also be that we ought to invent a mechanism to annotate a URL with
the length of the thing that is expected. Especially for data with a hash
that is supposed to match.
As for certificate chains: quantum safe certificate chains could be large.
1MB is not a good threshold here; 100Mb might be.
--
Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting )
Sandelman Software Works Inc, Ottawa and Worldwide
signature.asc
Description: PGP signature
_______________________________________________ COSE mailing list -- [email protected] To unsubscribe send an email to [email protected]
