Re: [TLS] Signature Hash Agility
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Signature Hash Agility



At Fri, 29 Jun 2007 09:06:10 -0700,
Eric Rescorla wrote:
> 
> 4. DSA hash selection
> I claim it must be deterministic from the DSA SubjectPublicKeyInfo what hash
> algorithm it is to be used with. Otherwise you risk substitution attacks.

So, where this item is at is that I think that for the OID dsa
(1 2 840 10040 4 1), we need to require SHA-1 and that PKIX
needs to require a new OID for dsaWithSHAXXX to go in the
SPKI.

I have a note in the draft, but it's not finished.

-Ekr

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.