Re: ECDSA test key/files
Aleksey Sanin <[email protected]> Wed, 15 Feb 2017 09:38:06 -0800
| Newsgroups | gmane.text.xml.xmlsec |
|---|---|
| Message-ID | <[email protected]> |
Here is the change that added tests and also added the note to the readme file with the commands used to generate the keys: https://github.com/lsh123/xmlsec/commit/8a234bb11183bd2f978365d089c2874c3351300e#diff-63b09e79322947706d90f6ac2ff46597 Aleksey On 2/15/17 3:22 AM, Miklos Vajna wrote: > Hi, > > I tried to look at supporting ECDSA in the nss backend. Here is a work > in progress code: > > https://github.com/vmiklos/xmlsec/tree/nss-ecdsa-wip > > (I'll send a pull request when it actually works.) > > It currently fails as it seems the enveloping-sha512-ecdsa-sha512.xml > test file is using an EC key where the parameter is secp256k1, which is > not supported by NSS. > > Here is a list of parameters supported by NSS: > > http://www.mail-archive.com/[email protected]/msg12766.html > > So based on that, perhaps I would start with secp256r1. Which leads to > the question I would like this ask: > > How are the ecdsa-secp256k1 test keys are generated? I found no commands > regarding them in tests/keys/README. > > If the documentation could be updated, then perhaps a way forward would > be adding ecdsa-secp256r1 testcases for openssl, and then I could > validate my NSS code by making sure the same tests pass for the NSS > backend as well. > > Thanks, > > Miklos > > > > _______________________________________________ > xmlsec mailing list > [email protected] > http://www.aleksey.com/mailman/listinfo/xmlsec > _______________________________________________ xmlsec mailing list [email protected] http://www.aleksey.com/mailman/listinfo/xmlsec
signature.asc
(application/pgp-signature, 842 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJYpJICAAoJEEEbi2vACtCg/S0P/iZK7QJkCjcpAkhhNuextked b6LzgKLHqTNPhgEDtFmxoT5jX/iFvvb5g6s7JjXQr08hvmPHUOamw9d1wyFH9QeT QIAmGcNO1GpPnIp7QH3nBoTM7S9I8tCP3dWhvE3eafj22bCJwOIdWipoZxQY4KVe ltOLYjPf+GB0PwuhZyVfJptD3wiQMd+NkRPNS/viaMh6DGZVb973Lv/wxsx6FoTx nfGy6xrIMh6+zLDy4zn5+T9F7AR6Yyxefufo3OcUcJrr+huJTDrohDF3XBCR3Omx W+T9YBCJN0QdWqY4W7x9kzWDuIl/F1ZhI66U0yfooFXe0hWSkY17bJ0UBtI2D5Qk 0HJRGMdU7M7rUTb1wvTePqMx3WiDxx2WbLalaZ/C+VIx9LKqL29/Q7ek6iuRcXQt 2GjS6+VBfCy1F9TL7qEK/EIxwQlk5xhvYN4OYwYGiINcvoQJtnPuXNVkPESmeiMT xGO9/WoDUfxXi+Q0piPVgBaf6OhatHlGvzhiCLA7XF0ahBQgbZGifJfh1Vx0BDL4 V2gpwm9X4Htgc/JzCSTzN7Qk8EvWLc8aZUZBoRQfxRoGlOYOOVi42Fi12dKUAGWz 5m9LOEZfUgKIEhgapbdi8ApAe1yk38TGhnE5eeEGTYpesLvIUya1Wxwev7FBycDT 2AQxeJJGQN94/J9+t8DF =bsOm -----END PGP SIGNATURE-----