<div dir="ltr"><div class="gmail_default" style="font-size:small">I want to emphasize <br class="gmail-Apple-interchange-newline"><table cellpadding="0" class="gmail-cf gmail-gJ" style="border-collapse:collapse;margin-top:0px;width:auto;font-family:"Google Sans",Roboto,RobotoDraft,Helvetica,Arial,sans-serif;font-size:14px;display:block"><tbody style="display:block"><tr class="gmail-acZ" style="height:auto;display:flex"><td class="gmail-gF gmail-gK" style="padding:0px;vertical-align:top;width:411.049px;line-height:20px;display:block;max-height:20px"><table cellpadding="0" class="gmail-cf gmail-ix" style="border-collapse:collapse;table-layout:fixed;width:411.049px"><tbody><tr><td class="gmail-c2" style="display:flex"><h3 class="gmail-iw gmail-gFxsud" style="overflow:hidden;font-size:0.75rem;margin:inherit;text-overflow:ellipsis;color:rgb(95,99,104);line-height:20px"><span class="gmail-qu" role="gridcell" tabindex="-1" style="outline:none"><span name="Pedro de Perdigão Lana" class="gmail-gD" style="color:rgb(31,31,31);font-size:0.875rem;display:inline;vertical-align:top;line-height:20px"><span style="vertical-align:top">Pedro de Perdigão Lana's point about periodic revalidation</span></span></span></h3></td></tr></tbody></table>and <span style="background-color:rgb(248,250,253);color:rgba(0,0,0,0.87);font-family:Roboto,RobotoDraft,Helvetica,Arial,sans-serif;font-size:18px">Yao Amevi A. Sossou's point about it being only one of several validation factors.</span></td><td class="gmail-gF gmail-gK" style="padding:0px;vertical-align:top;width:411.049px;line-height:20px;display:block;max-height:20px"><span style="background-color:rgb(248,250,253);color:rgba(0,0,0,0.87);font-family:Roboto,RobotoDraft,Helvetica,Arial,sans-serif;font-size:18px"><br></span></td><td class="gmail-gF gmail-gK" style="padding:0px;vertical-align:top;width:411.049px;line-height:20px;display:block;max-height:20px"><br></td></tr></tbody></table> </div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, May 1, 2025 at 8:40 PM Enrique Chaparro <<a href="mailto:echaparro@vialibre.org.ar">echaparro@vialibre.org.ar</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="auto"><div>it sounds stronger and more reasonable that LEAs generate a public/private key pair to authenticate themselves. the digest of the public key should be verified through a different channel — somewhat clumsy, perhaps, but it needs to be done only once during the key pair validity period.</div><div dir="auto"><br></div><div dir="auto">regards,</div><div dir="auto"><br></div><div dir="auto">Tx.</div><div><br></div><div>Freiheit ist immer Freiheit des Andersdenkenden.<br>-- Rosa Luxemburg</div></div>
</blockquote></div>