RE: Sample keys format

"Blake Ramsdell" <[email protected]> Tue, 17 Aug 1999 14:59:08 -0700
Newsgroups gmane.ietf.smime-examples
Message-ID <[email protected]>
> -----Original Message-----
> From: Dr Stephen Henson [mailto:[email protected]]
> Sent: Tuesday, August 17, 1999 2:52 PM
> To: '[email protected]'
> Subject: Re: Sample keys format
> 
> Blake Ramsdell wrote:
> > 
> > 1. Should the public keys be in RFC2459 
> SubjectPublicKeyInfo format (that
> > is, the AlgorithmIdentifier followed by BIT STRING wrapping 
> the public key).
> > 
> 
> As with Jim, no preference as long as its in the certificate.

I agree.

> > 2. Should the private keys be in PKCS #8 PrivateKeyInfo format:
> > 
> 
> For DSA and DH is there any other format? For RSA there is 
> PKCS#1 as an
> alternative.

I actually didn't know much about the "official" private key formats for DSA
and DH.  The original DSA keys from afarrell had just the bare INTEGER for
DSA and the PKCS #1 format for RSA.

I personally think that PKCS #8 is the right way to go for everything, but I
wonder whether or not we should do something about making this "more formal"
(that is, get the PKCS #8 definition into an RFC somewhere).  I may be
behind the times, and this effort is underway or completed.

Blake
--
Blake C. Ramsdell
Worldtalk Corporation
For current info, check http://www.deming.com/users/blaker
Voice +1 425 376 0225 x103  Fax +1 425 376 0915