Mozilla RSA-PSS policy

Hubert Kario <[email protected]>
Newsgroups gmane.comp.mozilla.crypto
Message-ID <[email protected]>
In response to comment made by Gervase Markham[1], pointing out that Mozilla 
doesn't have an official RSA-PSS usage policy.

This is the thread to discuss it and make a proposal that could be later 
included in Mozilla Root Store Policy[2]

I'm proposing the following additions to the Policy (leaving out exactly which 
sections this needs to be added, as that's better left for the end of 
discussion):

 - RSA keys can be used to make RSASSA-PKCS#1 v1.5 or RSASSA-PSS signatures on 
issued certificates
 - certificates containing RSA parameters can be limited to perform RSASSA-PSS 
signatures only by specifying the X.509 Subject Public Key Info algorithm 
identifier to RSA-PSS algorithm
 - end-entity certificates must not include RSA-PSS parameters in the Public 
Key Info Algorithm Identifier - that is, they must not be limited to creating 
signatures with only one specific hash algorithm
 - issuing certificates may include RSA-PSS parameters in the Public Key Info 
Algorithm Identifier, it's recommended that the hash selected matches the 
security of the key
 - signature hash and the hash used for mask generation must be the same both 
in public key parameters in certificate and in signature parameters
 - the salt length must equal at least 32 for SHA-256, 48 for SHA-384 and 64 
bytes for SHA-512
 - SHA-1 and SHA-224 are not acceptable for use with RSA-PSS algorithm

 1 - https://bugzilla.mozilla.org/show_bug.cgi?id=1400844#c15
 2 - https://www.mozilla.org/en-US/about/governance/policies/security-group/
certs/policy/
-- 
Regards,
Hubert Kario
Senior Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 115, 612 00  Brno, Czech Republic

-- 
dev-tech-crypto mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-tech-crypto
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCgAGBQJaFDeQAAoJEJKo0bgB0vX1BTwQAI+HtCb6pujqBWTKRFr0QWQL
TUCIKDq2BaJQU5rzlCebZm8/xLTpLuv4o3OOFzGVcZTArSUN9v7lIotaCXNzeTz6
OKXoO3tisYSqCo7+hmU0yB+U71jwDtsY6b4A2LjCpFYyOiEaGERN7nDOZHfjBw8n
a0uZI8jgPRd/Uv6RFjGhXAhUbX1z679xP8aqbHic9gomgBd2EuuQvZQrC+nG1NQ+
zR5OnG+rJ7Dyj1oh9Ovd5Drdu1otNs/aWs2MJ4Rh5PUyUx2furaj2Em4r8j44Uh9
skRhczSUP8G6TJ4yRzn1Tz5dhaXF5gZhaSPfzbSZLhGY6MbUwm2cYURWzNKxbU1i
IXxENsotMgg2FGrZ2BOA/Ce7uXCBwKm5AxNCUSZlbM2TJBrEPPdF1C0ZtHs0qAuY
a2pfyXfwm+cwtVqFnDfWVZxE3h1KPTs0WNgMuHjtoA2e0PD4MdcUrXaIUd3Up4qe
YIUXtxPd5s9AHwumgY63T2qswgJCJyWkXqFpGk8063+Sno5DdfFoIj5s491DZETl
Ps/cKekEWiY8MQlhNQIEcV94sW7JHQ1FqRyrF8P8vdv+zfKw9a9uPvFrprHUKdL4
Z5K9Di0ktaXGZdu8i01Yhu/nBawiaMBvI8LymASbbh5ZEsskvJ74IfiCjh/euYaU
+bvfKkivRtSPbNKYYRRc
=3zux
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.