Hash Transition Updates - PowerPoint PPT Presentation

1 / 6
About This Presentation
Title:

Hash Transition Updates

Description:

SHA-1 HASH of entire certificate. Optional issuer and serial number ... using both SHA-1 and SHA-256. Mallory removes the SHA-256 signature and 'successfully' ... – PowerPoint PPT presentation

Number of Views:12
Avg rating:3.0/5.0
Slides: 7
Provided by: jimsc4
Learn more at: https://www.ietf.org
Category:

less

Transcript and Presenter's Notes

Title: Hash Transition Updates


1
Hash Transition Updates
  • Jim Schaad
  • Soaring Hawk Consulting

2
ESSCertID
  • Currently
  • SHA-1 HASH of entire certificate
  • Optional issuer and serial number of cert
  • Proposed Update
  • HASH of entire certificate
  • Hash identifier of entire certificate
  • Optional issuer and serial number of cert

3
Parallel Signing Indicator
  • Problem Statement
  • Alice signs using both SHA-1 and SHA-256
  • Mallory removes the SHA-256 signature and
    successfully attacks SHA-1
  • Bob can do SHA-256, but does not know that the
    parallel signature has been removed

4
Solution
  • New signed attribute signaling that multiple
    signatures were applied
  • Must be computable BEFORE any signatures are
    applied
  • Must contain enough information to identify back
    to signatures in some fashion

5
Possible Data
  • Body Digest algorithm
  • Signature algorithm
  • Identification of public key used for signature

6
Questions
Write a Comment
User Comments (0)
About PowerShow.com