Re: [TLS] Signature Hash Agility
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Signature Hash Agility
At Fri, 29 Jun 2007 09:06:10 -0700,
Eric Rescorla wrote:
>
> 4. DSA hash selection
> I claim it must be deterministic from the DSA SubjectPublicKeyInfo what hash
> algorithm it is to be used with. Otherwise you risk substitution attacks.
So, where this item is at is that I think that for the OID dsa
(1 2 840 10040 4 1), we need to require SHA-1 and that PKIX
needs to require a new OID for dsaWithSHAXXX to go in the
SPKI.
I have a note in the draft, but it's not finished.
-Ekr
_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.