Re: Disclosure Signature (dratf-03 to 04)

kai <[email protected]> Tue, 15 Apr 2003 20:22:51 +0900
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
Hello.

If so, generator is required to use same algorithm as CA, 
then if CA takes SHA-512 generator must use same one.

That means generator cannot take different security level with CA (no choice).

And also, generator must get it's own certificate from CA, and keep it.

Regards,


At 08:49 03/04/14 -0400, Tom Taylor wrote:
>Sorry for the delay -- I've been very busy with an ITU-T meeting and 
>haven't had
>access to E-mail.
>
>We dropped that field because the algorithm should be available from the 
>certificate.
>
>Naohiro Fukuda wrote:
> > Hello,
> >
> > I have a question;
> >
> > Draft-03 contained "signature algorithm field" in 2.8.3, but Draft-04
> > deleted it.
> >
> > -> Could you tell me the reason?
> >
> > I think when we check the validity of signature,
> >
> >  1) get a public key from true certificate
> >  2) use the public key to decrypt the signature and get out a hash value
> >  3) calculate the hash of the entire key disclosure list
> >  4) match the both of the hashes to check the validity
> >
> > In this case, if we do not signature algorithm, I think we can not do 3).
> >
> > Best Regards,
> >
> >
> > 
>
>---------------------------------------------------------------------------
>------------- 
>
> >
> > Naohiro Fukuda
> > Matsushita Electric Works, Ltd.
> > Network Security Team
> > New Business Promotion Division
> > Address: 5-13-2, Mita, Minato-ku, Tokyo 108-8351, Japan
> > Tel: +81-3-3452-3390 Fax: +81-3-5442-9156
> > (MIC)  :7-8334-4856 (MIC-FAX)  :7-8334-4869
> > E-mail: [email protected]
> > English Homepage: http://www.netcocoon.com
> > Japanese Homepage: http://www.nais-netcocoon.com
> > 
>
>---------------------------------------------------------------------------
>------------- 
>
> >
> >
> >
> >