Re: RFC8410 / RFC8037 incompatibility

Jim Schaad <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
This has been filed as an errata.

-----Original Message-----
From: pkix <[email protected]> On Behalf Of Michael StJohns
Sent: Friday, August 28, 2020 9:58 AM
To: [email protected]
Subject: Re: [pkix] RFC8410 / RFC8037 incompatibility

Hi Jim -

For later reference, self-issued certs that are not self-signed generally
have an authority key identifier pointing to the right key.

Mike


On 8/28/2020 12:03 PM, Jim Schaad wrote:
> If you read the text, the certificate in 10.2 says it is self-issued 
> not self-signed.  The key used to sign the certificate is not the 
> private key of the public key in the certificate.  I don't remember 
> off the top of my head which of the EdDSA certs from that draft I used to
do the signature.
>
> jim
>
> -----Original Message-----
> From: pkix <[email protected]> On Behalf Of Anders Rundgren
> Sent: Friday, August 28, 2020 8:00 AM
> To: [email protected]
> Subject: [pkix] RFC8410 / RFC8037 incompatibility
>
> Hi Crypto Experts,
>
> Please pardon my ignorance regarding curve25519, but I ran into 
> problems [*] trying to recreate the sample certificate:
> https://tools.ietf.org/html/rfc8410#section-10.2
>
> Reading
> https://tools.ietf.org/html/rfc8037#section-3.2
> indicates that signing using an ECDH key MUST NOT be doable as well.
>
> Personally I don't see any use of a self-signed encryption certificate 
> so maybe this is just a bad example...kind of edge case.
>
> Regards,
> Anders
>
> *] java.security.InvalidKeyException: cannot identify EdDSA private 
> key
>
> _______________________________________________
> pkix mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/pkix
>
> _______________________________________________
> pkix mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/pkix


_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.