I considered retaining namespace-specific packing.  my concern is that
in the channel binding response you want to remove values.  This ends up
being a bit namespace specific because of VSAs but seems to argue for
the channel binding logic ending up getting stuck with a fair bit of
namespace specific logic.  I also really wanted to avoid more than one
length for a given attribute because that tends to cause problems in a
security protocol--they can get out of sync.  A blob of RADIUS stuff all
with its own length would not suffer from the length issue so much.

This is an area where I want us to decide quite quickly what the answer
is going to be, but where I don't have a hugely strong opinion on what
it is.
I threw something out to make forward progress.
So long as we can actually decide on something soon, I'm happy to change
to another way of encoding.

Emu mailing list

Reply via email to