>From: owner-openssl-us...@openssl.org On Behalf Of Erwann Abalea
>Sent: Tuesday, 29 May, 2012 10:13

>Yes to everything.

Minor caveat: OpenSSL supports signatures using SHA256 
*with RSA and ECDSA* back to 0.9.8 and I think 0.9.7, 
but SHA256 (and SHA224) with DSA only since 1.0.0. 
(As I recall SHA2-RSA schemes were defined when SHA2 first 
came out in early noughties, and SHA2-ECDSA when ECDSA 
came out roughly the same time, but SHA2-DSA only when 
DSA was increased above 1024 by FIPS 186-3 in 2008.)

>As your question is not about the development of OpenSSL, 
>but instead about its use, it should have been better in 
>the openssl-users mailing list.

Yes.
        
>Le 28/05/2012 15:43, Manas Ranjan Lenka a écrit : 

<snip: want X509v3 RFC5280 with KU, BC, AKI, SKI, SHA256>

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to