pkix-7----Page:13
1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  16  17  18  19  20  21  22  23  24  25 

Interoperability with IETF Protocols, I
New algorithm OIDs or critical extensions are inherently incompatible with current protocols/implementations
Limitations on ancillary cryptographic algorithms may be incompatible with protocol details
For DH/MQV, kdfs tend to be unique to protocols
For ECDSA, hash algorithm is already specified in the protocol stream. Specification in cert creates new verification steps.
PPT Version