RE: Sample keys format
"Blake Ramsdell" <[email protected]> Tue, 17 Aug 1999 14:59:08 -0700
| Newsgroups | gmane.ietf.smime-examples |
|---|---|
| Message-ID | <[email protected]> |
> -----Original Message----- > From: Dr Stephen Henson [mailto:[email protected]] > Sent: Tuesday, August 17, 1999 2:52 PM > To: '[email protected]' > Subject: Re: Sample keys format > > Blake Ramsdell wrote: > > > > 1. Should the public keys be in RFC2459 > SubjectPublicKeyInfo format (that > > is, the AlgorithmIdentifier followed by BIT STRING wrapping > the public key). > > > > As with Jim, no preference as long as its in the certificate. I agree. > > 2. Should the private keys be in PKCS #8 PrivateKeyInfo format: > > > > For DSA and DH is there any other format? For RSA there is > PKCS#1 as an > alternative. I actually didn't know much about the "official" private key formats for DSA and DH. The original DSA keys from afarrell had just the bare INTEGER for DSA and the PKCS #1 format for RSA. I personally think that PKCS #8 is the right way to go for everything, but I wonder whether or not we should do something about making this "more formal" (that is, get the PKCS #8 definition into an RFC somewhere). I may be behind the times, and this effort is underway or completed. Blake -- Blake C. Ramsdell Worldtalk Corporation For current info, check http://www.deming.com/users/blaker Voice +1 425 376 0225 x103 Fax +1 425 376 0915