Re: Keys and Certificates creations

Peter Gutmann <[email protected]> Wed, 13 Feb 2013 10:33:40 +1300
Newsgroups gmane.comp.encryption.cryptlib
Message-ID <[email protected]>
"Miller, Timothy J." <[email protected]> writes:

>Any of the DH/DHE DSS cipher suites should work, but you have to set the
>keyAgreement keyUsage in the server cert.

The reason why cryptlib requires RSA certs is that in the past something like,
oh, about 100% of users who tried to use DSA thought it was a drop-in
replacement for RSA, and then wondered why things didn't work.  Given the
practical non-use of DSA (I think the last SSL scan identified a dozen or so
DSA-using servers on the entire planet) it was easiest (meaning the least
confusion caused for users) to just require RSA.

Peter.


_______________________________________________
Cryptlib mailing list
[email protected] via Mail: [email protected]
Archive: ftp://ftp.franken.de/pub/crypt/cryptlib/archives/
http://news.gmane.org/gmane.comp.encryption.cryptlib
Posts from non-subscribed addresses are blocked to prevent spam, please
subscribe in order to post messages.