Re: [TLS] TLS document status update
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] TLS document status update



>> But how could the substitution attack even succeed?  You would need
>> to create a valid CA signature on the replacement certificate, which
>> should not be possible.
> 
> Why not? All you need is a CA which doesn't require technical
> Proof of Possession of the private key.

If you can't trust your own CA, then by all means send the hash.

The discussion is about whether a client MUST send the hash.  So
far it seems like SHOULD is the most appropriate, with relevant
comments in Security Considerations.

Mike
_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.