Re: RSA // OAEP // SHA-1

2013-01-30 Thread Avi
Would it make sense to amend that to add SHA-3? --Avi On 1/30/13, Michel Messerschmidt wrote: > On Tue, Jan 29, 2013 at 06:36:25PM -0600, John Clizbe wrote: >> ved...@nym.hush.com wrote: >> > if so, would this fall under the open-pgp RFC, or would it have to go >> > through an >> > RSA standard

Re: RSA // OAEP // SHA-1

2013-01-30 Thread vedaal
On Wednesday, January 30, 2013 at 3:28 PM, "Michel Messerschmidt" wrote: > >Although it is the default, RFC 3447 is not restricted to SHA-1. >Appendix B actually states: >"For the RSAES-OAEP encryption scheme and EMSA-PSS encoding >method, >only SHA-1 and SHA-256/384/512 are recommended." Wh

Re: RSA // OAEP // SHA-1

2013-01-30 Thread Michel Messerschmidt
On Tue, Jan 29, 2013 at 06:36:25PM -0600, John Clizbe wrote: > ved...@nym.hush.com wrote: > > if so, would this fall under the open-pgp RFC, or would it have to go > > through an > > RSA standard first? > > RFC 4880 makes no mention of OAEP. RFC 4880 references RFC 3447 for details of > RSA imple