Re: draft-ietf-itrace-03.txt
Mikael Olsson <[email protected]> Sat, 18 Jan 2003 14:09:19 +0100
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
[ Sent to the list, even though your mail was off-list. I assume you wouldn't write "can someone check...?" in a mail meant for me only. ;) ] Marcus Leech wrote: > > Mikael Olsson wrote: > > > > Maybe that is true for the public key encryption algorithm. > > (Can't say for sure; my X.509 knowledge is hazy at best.) > > > > However, I'm fairly certain that X.509 certs have no info whatsoever > > about hashing algorithms used to produce signatures. We would at > > _least_ need to specify that much in the actual itrace packets. > > > I thought they did--the cert would at least have to specify the hash > algorithm used in the signature of the cert itself. Can someone > check the relevant PKIX documents. Yeah, the certificate would need to specify the hash used in signing the cert itself, but that doesn't mean that one can't use a completely different hash for singing something else. Now, maybe I'm missing something. There is definately no technical reason for mandating a certain hash in relation to a signature, but that doesn't necessarily mean that the X.509 specification doesn't do just that. I'm just saying "I don't know for sure", so I'll echo Marcus' question: does anyone here have sufficient X.509 clue to answer this authoratively? /Mikael -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com