Re: RFC8410 / RFC8037 incompatibility

Michael StJohns <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Hi Jim -

For later reference, self-issued certs that are not self-signed 
generally have an authority key identifier pointing to the right key.

Mike


On 8/28/2020 12:03 PM, Jim Schaad wrote:
> If you read the text, the certificate in 10.2 says it is self-issued not
> self-signed.  The key used to sign the certificate is not the private key of
> the public key in the certificate.  I don't remember off the top of my head
> which of the EdDSA certs from that draft I used to do the signature.
>
> jim
>
> -----Original Message-----
> From: pkix <[email protected]> On Behalf Of Anders Rundgren
> Sent: Friday, August 28, 2020 8:00 AM
> To: [email protected]
> Subject: [pkix] RFC8410 / RFC8037 incompatibility
>
> Hi Crypto Experts,
>
> Please pardon my ignorance regarding curve25519, but I ran into problems [*]
> trying to recreate the sample certificate:
> https://tools.ietf.org/html/rfc8410#section-10.2
>
> Reading
> https://tools.ietf.org/html/rfc8037#section-3.2
> indicates that signing using an ECDH key MUST NOT be doable as well.
>
> Personally I don't see any use of a self-signed encryption certificate so
> maybe this is just a bad example...kind of edge case.
>
> Regards,
> Anders
>
> *] java.security.InvalidKeyException: cannot identify EdDSA private key
>
> _______________________________________________
> pkix mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/pkix
>
> _______________________________________________
> pkix mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.