Forgive my curiosity, but could you please expand on that? We designed the composite certificates/signatures to act like "just another signature algorithm" (if you don't peek into the innards and I don't know why anything other than the low level crypto would need to).
Now, there might well be something I'm missing. Please, enlighten me as to what that may be. My personal opinion: I see the need for both pure and hybrid authentication. However, the hybrid authentication needn't be composite certificates - dual (aka parallel) certificates would address the need just as well. I like composite certificates because it contains almost all the complexity into the crypto engine (with everything else being essentially unchanged) - if my hope is misguided, then, again, enlighten me. ________________________________ From: Ilari Liusvaara <[email protected]> Sent: Tuesday, July 14, 2026 1:44 PM To: <[email protected]> <[email protected]> Subject: [TLS] Re: Fwd: New Version Notification for draft-yusef-tls-pqt-dual-certs-02.txt As an operator, I can say that issuing composite certificate is a big deal, even with automation like ACME. Because it involves actions that can not be feasibly automated.
_______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
