Re: Content-MD5

M. Hedlund writes:
> At 9:21 AM 11/6/95, Laurent Demailly wrote (quoting Dave Kristol):
[Dave Kristol]
> > > I have headers
> > >      Content-MD5: xyz
> > >      Content-SHA: qrs
> > > The recipient computes the digests of the message and finds that the MD5
> > > digest matches xyz, but the SHA digest does not match qrs.  Now what?
> > > I imagine we assume the integrity to be compromised.
> > > With a single Content-Digest header, there's no ambiguity.
[Laurent Demailly]
> >Ahem, the mecanism I suggested does not state you have only one
> >algorithm key pair, you can have one or more (maybe that's not a good
> >thing, and can be changed,... but..)
[M. Hedlund]
> No, you want to be able to have more than one digest.  From RFC 1810,
> "Report on MD5 Performance," (last para. of "Security Considerations"):
[Endre Balint Nagy]
Until we not specify some digest-negotiation scheme, servers will compute
and send all digests they can compute in hope that the client undertands 
at least one of them.
BTW. Using SHA is legal outside US?

