Re: Policy 2.7 Proposal: Clarify Section 5.1 ECDSA Curve-Hash Requirements

2019-11-08 Thread Ryan Sleevi via dev-security-policy
On Fri, Nov 8, 2019 at 1:54 PM Wayne Thayer via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > A few more questions have come up about this change: > > * Since mozilla::pkix doesn't currently support the RSA-PSS encodings, why > would we include them in our policy? > They w

Re: Policy 2.7 Proposal: Clarify Section 5.1 ECDSA Curve-Hash Requirements

2019-11-08 Thread Wayne Thayer via dev-security-policy
A few more questions have come up about this change: * Since mozilla::pkix doesn't currently support the RSA-PSS encodings, why would we include them in our policy? * Related: would this detailed enumeration of requirements be better to place in the BRs than in Mozilla policy? * In that case i