1 Feb 1998 19:53
Re: Key Usage
Simonetti David <simonetti_david <at> bah.com>
1998-02-01 18:53:42 GMT
1998-02-01 18:53:42 GMT
Rodney, I had forwarded the following shortly after the Washington meeting. The minimal response I received was favorable, but I never received an absolute response from the PKIX-1 authors... Tim (et al), As you stated at the meeting last week with respect to the key usage profile, I agree that PKIX should not restrict the bit combinations. However, I think the previous discussions on this topic proved obvious that there are multiple interpretations of these bits. In an attempt to clarify the meaning of several of the bits, I suggest the following editorial changes to PKIX-1: Section 4.2.1.3, paragraph beginning with "The digitalSignature bit is asserted...", add the following, "The digitalSignature bit should be set when the key is for use in ephemeral applications, e.g., for a single session authentication application." Paragraph beginning with "The nonRepudiation bit is asserted...", add the following, "The nonRepudiation bit should be set when when the key is used to sign an object which may require the validation of the signature at a future time." I also suggest adding, "If the key may be used for both digitalSignature and nonRepudiation applications, both bits may be set." Finally, after the descriptions of encipherOnly and decipherOnly I(Continue reading)
RSS Feed