Re: RFC8410 / RFC8037 incompatibility

"StJohns, Michael" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <CANeU+ZD28wREUW4yZoj=YyrFoCyNwV8R=LcMiBW_sRy=BbH6dw@mail.gmail.com>
Thanks!

On Fri, Aug 28, 2020 at 13:40 Jim Schaad <[email protected]> wrote:

> This has been filed as an errata.
>
>
>
> -----Original Message-----
>
> From: pkix <[email protected]> On Behalf Of Michael StJohns
>
> Sent: Friday, August 28, 2020 9:58 AM
>
> To: [email protected]
>
> Subject: Re: [pkix] RFC8410 / RFC8037 incompatibility
>
>
>
> Hi Jim -
>
>
>
> For later reference, self-issued certs that are not self-signed generally
>
> have an authority key identifier pointing to the right key.
>
>
>
> Mike
>
>
>
>
>
> On 8/28/2020 12:03 PM, Jim Schaad wrote:
>
> > If you read the text, the certificate in 10.2 says it is self-issued
>
> > not self-signed.  The key used to sign the certificate is not the
>
> > private key of the public key in the certificate.  I don't remember
>
> > off the top of my head which of the EdDSA certs from that draft I used to
>
> do the signature.
>
> >
>
> > jim
>
> >
>
> > -----Original Message-----
>
> > From: pkix <[email protected]> On Behalf Of Anders Rundgren
>
> > Sent: Friday, August 28, 2020 8:00 AM
>
> > To: [email protected]
>
> > Subject: [pkix] RFC8410 / RFC8037 incompatibility
>
> >
>
> > Hi Crypto Experts,
>
> >
>
> > Please pardon my ignorance regarding curve25519, but I ran into
>
> > problems [*] trying to recreate the sample certificate:
>
> > https://tools.ietf.org/html/rfc8410#section-10.2
>
> >
>
> > Reading
>
> > https://tools.ietf.org/html/rfc8037#section-3.2
>
> > indicates that signing using an ECDH key MUST NOT be doable as well.
>
> >
>
> > Personally I don't see any use of a self-signed encryption certificate
>
> > so maybe this is just a bad example...kind of edge case.
>
> >
>
> > Regards,
>
> > Anders
>
> >
>
> > *] java.security.InvalidKeyException: cannot identify EdDSA private
>
> > key
>
> >
>
> > _______________________________________________
>
> > pkix mailing list
>
> > [email protected]
>
> > https://www.ietf.org/mailman/listinfo/pkix
>
> >
>
> > _______________________________________________
>
> > pkix mailing list
>
> > [email protected]
>
> > https://www.ietf.org/mailman/listinfo/pkix
>
>
>
>
>
> _______________________________________________
>
> pkix mailing list
>
> [email protected]
>
> https://www.ietf.org/mailman/listinfo/pkix
>
>
>
>

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.