Re: [TLS] Consensus call for certificate URL extension
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Consensus call for certificate URL extension
On Sep 23, 2008, at 9:03 PM, Mike wrote:
The problem with either of these options is that it gives the
impression
that adding the hash improves security. As I mentioned before, if
all a
client does to determine the hash is download the certificate and
compute
its value, then it may just be validating a bogus certificate.
I would hope that the client downloads the certificate, and verifies
that the private key that it holds matches the public key in the
certificate before calculating the hash.
Whether the client does or does not hold the certificate, it must hold
the private key.
_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.