> It follows the RFC3280 recommendation in 4.2.1.2 (1): > > The keyIdentifier is composed of the 160-bit SHA-1 hash of the > value of the BIT STRING subjectPublicKey (excluding the tag, > length, and number of unused bits).
thanks. sorry, i missed that point while reading. well i'm not exactly sure... would hashing the DER encoded ASN.1 RSAPublicKey object sufficient for this recommandation? if not, how do i know, which bits are unused? -- +++ NEU bei GMX und erstmalig in Deutschland: TÜV-geprüfter Virenschutz +++ 100% Virenerkennung nach Wildlist. Infos: http://www.gmx.net/virenschutz ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]