Re: Key Identifier in X509v3 extensions

2004-03-05 Thread Dr. Stephen Henson
On Fri, Mar 05, 2004, Claus Nagel wrote: > > It follows the RFC3280 recommendation in 4.2.1.2 (1): > > > > The keyIdentifier is composed of the 160-bit SHA-1 hash of the > > value of the BIT STRING subjectPublicKey (excluding the tag, > > length, and number of unuse

Re: Key Identifier in X509v3 extensions

2004-03-05 Thread Claus Nagel
> It follows the RFC3280 recommendation in 4.2.1.2 (1): > > The keyIdentifier is composed of the 160-bit SHA-1 hash of the >value of the BIT STRING subjectPublicKey (excluding the tag, >length, and number of unused bits). thanks. sorry, i missed that point whi

Re: Key Identifier in X509v3 extensions

2004-03-05 Thread Dr. Stephen Henson
On Fri, Mar 05, 2004, Claus Nagel wrote: > > The SKID can be calculated automatically by the extension code (see > > doc/openssl.txt). The AKID is normally copied from the SKID of the issuers > > certificate. > > As for the SKID I found the following in the openssl.txt: > Example: subjectKeyIdent

Re: Key Identifier in X509v3 extensions

2004-03-05 Thread Claus Nagel
> The SKID can be calculated automatically by the extension code (see > doc/openssl.txt). The AKID is normally copied from the SKID of the issuers > certificate. As for the SKID I found the following in the openssl.txt: Example: subjectKeyIdentifier=hash But which values are taken to calculate tha

Re: Key Identifier in X509v3 extensions

2004-03-05 Thread Dr. Stephen Henson
On Fri, Mar 05, 2004, Claus Nagel wrote: > hello, > how do i compute the values for X509v3 Subject Key Identifier and X509v3 > Authority Key Identifier{keyid} in a X509v3 certificate? And where can I store > MD5 or SHA1 thumbprints in a X509v3 certificate? > thx, The SKID can be calculated automa

Key Identifier in X509v3 extensions

2004-03-05 Thread Claus Nagel
hello, how do i compute the values for X509v3 Subject Key Identifier and X509v3 Authority Key Identifier{keyid} in a X509v3 certificate? And where can I store MD5 or SHA1 thumbprints in a X509v3 certificate? thx, Claus Nagel -- +++ NEU bei GMX und erstmalig in Deutschland: TÜV-geprüfter Virenschu