Re: [TLS] Consensus call for certificate URL extension
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] Consensus call for certificate URL extension




On Sep 23, 2008, at 9:03 PM, Mike wrote:
The problem with either of these options is that it gives the impression that adding the hash improves security. As I mentioned before, if all a client does to determine the hash is download the certificate and compute
its value, then it may just be validating a bogus certificate.

I would hope that the client downloads the certificate, and verifies that the private key that it holds matches the public key in the certificate before calculating the hash.

Whether the client does or does not hold the certificate, it must hold the private key.
_______________________________________________
TLS mailing list
TLS at ietf.org
https://www.ietf.org/mailman/listinfo/tls



Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.