2 Mar 2005 00:38
Fwd: [saag] X.509 certificate collision, via MD5 collisions
David A. McGrew <mcgrew <at> cisco.com>
2005-03-01 23:38:33 GMT
2005-03-01 23:38:33 GMT
FYI. Comments welcome. David Begin forwarded message: > From: Russ Housley <housley <at> vigilsec.com> > Date: March 1, 2005 3:24:00 PM PST > To: saag <at> mit.edu, ietf-pkix <at> imc.org > Subject: [saag] X.509 certificate collision, via MD5 collisions > > I have not had an opportunity to review this document yet, but the > findings need to be shared with the whole Internet security community. > >> We announce a method for the construction of pairs of valid X.509 >> certificates in which the "to >> be signed" parts form a collision for the MD5 hash function. As a >> result the issuer signatures >> in the certificates will be the same when the issuer uses MD5 as its >> hash function. > > http://eprint.iacr.org/2005/067 > > > > _______________________________________________ > saag mailing list > saag <at> mit.edu > https://jis.mit.edu/mailman/listinfo/saag >(Continue reading)
RSS Feed