force-v4-certs and digest-algo

Len Sassaman rabbi at
Fri May 10 01:29:02 CEST 2002

On Thu, 9 May 2002, Brian M. Carlson wrote:

> > First of all: RIPEMD-160 is neither a MUST or a SHOULD. (It's neither a
> > required, not suggested, algorithm in OpenPGP. Don't be surprised if
> > implementations do not support or understand RIPEMD-160 signatures).
> While this may be true, it is a de facto SHOULD, just like IDEA is.

Untrue. If it isn't listed as SHOULD in the document, it isn't a SHOULD.
There are no "de facto SHOULDs."

IDEA is a SHOULD in RFC 2440. Its status has since changed, I believe.

