You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<p id="section-5.3.3-1">The cosigner's public key specifies both the key material and the signature algorithm to use with the key material. In order to change key or signature parameters, a cosigner operator MUST deploy a new cosigner, with a new cosigner ID. Signature algorithms MUST fully specify the algorithm parameters, such as hash functions used.<a href="#section-5.3.3-1" class="pilcrow">¶</a></p>
4422
-
<p id="section-5.3.3-2">In this document, any PKIX signature algorithm MAY be used, such as the ML-DSA algorithms defined in <span>[<a href="#RFC9881" class="cite xref">RFC9881</a>]</span>. The signature is generated as in PKIX, except that the input is the structure defined in <a href="#signature-format" class="auto internal xref">Section 5.3.1</a>. In particular, in ML-DSA algorithms, the context string MUST be an empty string, as in <span><a href="https://rfc-editor.org/rfc/rfc9881#section-3" class="relref">Section 3</a> of [<a href="#RFC9881" class="cite xref">RFC9881</a>]</span>.<a href="#section-5.3.3-2" class="pilcrow">¶</a></p>
4423
-
<p id="section-5.3.3-3">Other documents or deployments MAY define other signature schemes and formats. Log clients that accept cosignatures from some cosigner are assumed to be configured with all parameters necessary to verify that cosigner's signatures, including the signature algorithm and version of the signature format.<a href="#section-5.3.3-3" class="pilcrow">¶</a></p>
4421
+
<p id="section-5.3.3-1">The cosigner's public key specifies both the key material and the signature algorithm to use with the key material. In order to change key or signature parameters, a cosigner operator MUST deploy a new cosigner, with a new cosigner ID. Signature algorithms MUST fully specify the algorithm parameters, such as hash functions used. Signatures are computed over the CosignedMessage described in <a href="#signature-format" class="auto internal xref">Section 5.3.1</a>.<a href="#section-5.3.3-1" class="pilcrow">¶</a></p>
4422
+
<p id="section-5.3.3-2">Log clients that accept cosignatures from some cosigner are assumed to be configured with all parameters necessary to verify that cosigner's signatures, including the signature algorithm and version of the signature format.<a href="#section-5.3.3-2" class="pilcrow">¶</a></p>
0 commit comments