disco
disco copied to clipboard
PKI: signed identity needs to be signed
in handshake patterns with X or I when the key needs to be signed: we also need to sign the server "identity name" which the client needs to know in advance.
Perhaps we can even sign the ca pubkey and pass the ca pubkey in the payload. Just want to avoid dsks without thinking too much about it.