<div dir="auto"><div>it sounds stronger and more reasonable that LEAs generate a public/private key pair to authenticate themselves. the digest of the public key should be verified through a different channel — somewhat clumsy, perhaps, but it needs to be done only once during the key pair validity period.</div><div dir="auto"><br></div><div dir="auto">regards,</div><div dir="auto"><br></div><div dir="auto">Tx.</div><div><br></div><div data-smartmail="gmail_signature">Freiheit ist immer Freiheit des Andersdenkenden.<br>-- Rosa Luxemburg</div></div>