Re: draft-ietf-itrace-03.txt

Mikael Olsson <[email protected]> Sat, 18 Jan 2003 14:09:19 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>
[ Sent to the list, even though your mail was off-list.  I assume you 
  wouldn't write "can someone check...?" in a mail meant for me only. ;) ]

Marcus Leech wrote:
> 
> Mikael Olsson wrote:
> >
> > Maybe that is true for the public key encryption algorithm.
> > (Can't say for sure; my X.509 knowledge is hazy at best.)
> >
> > However, I'm fairly certain that X.509 certs have no info whatsoever
> > about hashing algorithms used to produce signatures.  We would at
> > _least_ need to specify that much in the actual itrace packets.
> >
> I thought they did--the cert would at least have to specify the hash
>   algorithm used in the signature of the cert itself.  Can someone
>   check the relevant PKIX documents.

Yeah, the certificate would need to specify the hash used in 
signing the cert itself, but that doesn't mean that one can't
use a completely different hash for singing something else.

Now, maybe I'm missing something. There is definately no technical
reason for mandating a certain hash in relation to a signature, but
that doesn't necessarily mean that the X.509 specification doesn't do 
just that. 

I'm just saying "I don't know for sure", so I'll echo Marcus' 
question: does anyone here have sufficient X.509 clue to
answer this authoratively?

/Mikael

-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com