Re: Hash Algorithm for X.509 certificate.
Tom Taylor <[email protected]> Tue, 18 Feb 2003 19:24:00 -0500
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
Just thought I'd clean this one up, since I consulted RFCs 3279 and 3280 in the process of reworking the ITrace draft. Yes, an X.509 certificate identifies the signature algorithm and, as part of that, the hash function. But the point stands that the certificate algorithms aren't necessarily the ones used to create the ITrace packet HMAC. [ Sent to the list, even though your mail was off-list. I assume you wouldn't write "can someone check...?" in a mail meant for me only. ;) ] Marcus Leech wrote: > > Mikael Olsson wrote: > > > > Maybe that is true for the public key encryption algorithm. (Can't > > say for sure; my X.509 knowledge is hazy at best.) > > > > However, I'm fairly certain that X.509 certs have no info whatsoever > > about hashing algorithms used to produce signatures. We would at > > _least_ need to specify that much in the actual itrace packets. > > > I thought they did--the cert would at least have to specify the hash > algorithm used in the signature of the cert itself. Can someone > check the relevant PKIX documents. Yeah, the certificate would need to specify the hash used in signing the cert itself, but that doesn't mean that one can't use a completely different hash for singing something else. Now, maybe I'm missing something. There is definately no technical reason for mandating a certain hash in relation to a signature, but that doesn't necessarily mean that the X.509 specification doesn't do just that. I'm just saying "I don't know for sure", so I'll echo Marcus' question: does anyone here have sufficient X.509 clue to answer this authoratively? /Mikael -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com