Re: Public Key algorithm agility in CGAs
Hello Marcelo,
As Sean stated, we (Michaela, Sean, Maryline and I) are currently working on
some solutions for the problems you exposed. Unfortunately, we didn't finish
writing the drafts yet. The comments during the last WG meeting provided us
some really good insight. We hope this discussion will make clearer what is
possible and what is not.
I will try to explain how we envision to solve theses problems. Comments
inline.
On Sun, 14 Dec 2008, marcelo bagnulo braun wrote:
> Hi,
>
> there have been some discussion about how to support multiple public key
> algorithms in CGAs.
We think multiple keys can be a good transition mechanism in network
that are (or will be) deployed with 3971 version of SEND. I explain why
this is good and how we can make it backward compatible with the actual
SEND specification.
> RFC3972 states that only RSA are supported and there is a mandatory Public
> Key filed in the CGA PDS that contains:
>
> The public key MUST be formatted as a DER-encoded
> [ITU.X690.2002] ASN.1 structure of the type SubjectPublicKeyInfo,
> defined in the Internet X.509 certificate profile [RFC3280]. SEND
> SHOULD use an RSA public/private key pair. When RSA is used, the
> algorithm identifier MUST be rsaEncryption, which is
(Continue reading)