Re: [x500standard] AW: Redundant signature algorithm info in certs.
"Santosh Chokhani" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hello Sir, There was some work done in the area of trusted archive by the LTANS working group. You should look at things like RFC 5276 and RFC 4998. These include archiving certificates and revocation information. From: [email protected] [mailto:[email protected]] On Behalf Of Hans-Rudolf Thomann Sent: Wednesday, May 25, 2016 4:08 AM To: [email protected]; 'PKIX' <[email protected]> Subject: [x500standard] AW: Redundant signature algorithm info in certs. A possibly related question: When archiving a signed document, what do you do with the certificate? You will need it for future origin authentication. Im not aware for a need of the algo info in the signature, but one for the whole certificate in archived documents. Mit freundlichen Grüssen Hans-Rudolf Thomann Von: [email protected] <mailto:[email protected]> [mailto:[email protected]] Im Auftrag von Erik Andersen Gesendet: Dienstag, 24. Mai 2016 15:07 An: PKIX <[email protected] <mailto:[email protected]> >; Directory list <[email protected] <mailto:[email protected]> > Betreff: [x500standard] Redundant signature algorithm info in certs. The question about apparently redundant signature algorithm information in public-key certificates, attribute certificates and CRLs has been raised before. It seems clear that by including the signature algorithm within the body of the cert, it is protected by the signature. But why does the algorithm then has to be part of the signature itself? I am not suggesting to change current specifications. The question could be relevant for new signed structures developed by other specifications. Erik _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix