Forgive my curiosity, but could you please expand on that?

We designed the composite certificates/signatures to act like "just another 
signature algorithm" (if you don't peek into the innards and I don't know why 
anything other than the low level crypto would need to).

Now, there might well be something I'm missing.  Please, enlighten me as to 
what that may be.

My personal opinion: I see the need for both pure and hybrid authentication.  
However, the hybrid authentication needn't be composite certificates - dual 
(aka parallel) certificates would address the need just as well.  I like 
composite certificates because it contains almost all the complexity into the 
crypto engine (with everything else being essentially unchanged) - if my hope 
is misguided, then, again, enlighten me.

________________________________
From: Ilari Liusvaara <[email protected]>
Sent: Tuesday, July 14, 2026 1:44 PM
To: <[email protected]> <[email protected]>
Subject: [TLS] Re: Fwd: New Version Notification for 
draft-yusef-tls-pqt-dual-certs-02.txt

As an operator, I can say that issuing composite certificate is a big
deal, even with automation like ACME. Because it involves actions that
can not be feasibly automated.

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to