Re: Minor comments on Section 4

> To tighten that up how about, "Serialization MAY be done by the encryptor,
> otherwise it MUST be done by the application."

It seems more clear if you break it into two sentences:
	The encryptor MAY do serialization.
	If the encryptor does not serialize, then the application MUST
	do serialization.

"does not serialize" isn't great, but "doesn't do it" doesn't do it for
me. :0
	/r$
-- 
Zolera Systems, Your Key to Online Integrity
Securing Web services: XML, SOAP, Dig-sig, Encryption
http://www.zolera.com

Received on Thursday, 20 September 2001 16:24:50 UTC