| | [No title] (Site not responding. Last check: 2007-10-26) |
 | | Algorithm Interoperability rules To maximize efficiency and minimize algorithm interoperability problems, the Federal PKI should be designed so that two end-entities who use the same signature algorithm, should be able to find a certification path that does not require use of a second algorithm. |
 | | Since compromise of the CA private key does not itself compromise the private keys of its subordinates (although it may allow the forgery of new certificates), it is not, in general necessary to replace the subordinate public-private key pairs, and the new certificates may retain the old user public key. |
 | | If the algorithms used are not FIPS approved, a FIPS waiver may be required; In general, it is the algorithm used in the key management certificate of the destination of an encrypted message that determines the key management algorithm used to establish the key the message encryption key. |
| www.va.gov /proj/vapki/documents/PKICON980904.doc (14579 words) |