Hi dkg,
Sorry to put you on the spot but I haven't been able to establish
contact with any of the other authors of draft-zhang-trans-ct-dnssec
yet.
I have two questions / suggestions:
- Remove issuer_key_hash
The draft refers to 6962-bis but "issuer_key_hash" was removed in -05.
The issuer_key_hash is useful for pre-certs but not for DNSSEC
AFAICT. Bu maybe I'm missing something?
- Define BinaryDigest in SignedCertificateTimestamp
The signed_entry struct in SignedCertificateTimestamp has two types of
type BinaryDigest. Should the type be DSRR? Why two?
Thanks!