At 10:28 PM 11/19/2003 +0000, Nick Pope wrote:
>-----Original Message-----
>From: Trevor Perrin [mailto:]
>Sent: 19 November 2003 20:08
>To: Nick Pope;
>Subject: RE: [dss] plans for next draft
>
>
>At 04:55 PM 11/19/2003 +0000, Nick Pope wrote:
>
> >Trevor,
> >
> >I agree - this allows time-stamps to be created and verified as any other
> >object.
> >
> >To be realy tidy should the description of <dss:timestamp> being within
> ><dss:signature> be part of that profile as a timestamp isn't just a normal
> >signature and should be linked to a specific request option.
>
>Right now there's no request option for saying what type of signature to
>return (XML signature, PGP signature, CMS signature, stored-digest
>signature, XML Timestamp, RFC 3161 Timestamp, etc...).
>
>Do you think we need an option for that? Or can we assume this is implicit
>in the ServiceProfile / ServicePolicy?
>
><np>I would suggest that a profile / policy could imply a set of options.
Agreed. But a profile/policy might also imply some things that *aren't*
options. So I'm wondering if "type of signature to produce" (i.e. XML-DSIG
/ PGP / CMS / XML-TST / RFC3161-TST) should be an option.
Probably it doesn't hurt to make it one, though for most profiles it would
be implicit - i.e., the profile would only support a single type of signature.
Trevor