Re: RFC8410 / RFC8037 incompatibility
Michael StJohns <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hi Jim - For later reference, self-issued certs that are not self-signed generally have an authority key identifier pointing to the right key. Mike On 8/28/2020 12:03 PM, Jim Schaad wrote: > If you read the text, the certificate in 10.2 says it is self-issued not > self-signed. The key used to sign the certificate is not the private key of > the public key in the certificate. I don't remember off the top of my head > which of the EdDSA certs from that draft I used to do the signature. > > jim > > -----Original Message----- > From: pkix <[email protected]> On Behalf Of Anders Rundgren > Sent: Friday, August 28, 2020 8:00 AM > To: [email protected] > Subject: [pkix] RFC8410 / RFC8037 incompatibility > > Hi Crypto Experts, > > Please pardon my ignorance regarding curve25519, but I ran into problems [*] > trying to recreate the sample certificate: > https://tools.ietf.org/html/rfc8410#section-10.2 > > Reading > https://tools.ietf.org/html/rfc8037#section-3.2 > indicates that signing using an ECDH key MUST NOT be doable as well. > > Personally I don't see any use of a self-signed encryption certificate so > maybe this is just a bad example...kind of edge case. > > Regards, > Anders > > *] java.security.InvalidKeyException: cannot identify EdDSA private key > > _______________________________________________ > pkix mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/pkix > > _______________________________________________ > pkix mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/pkix