[52068] in cryptography@c2.net mail archive
RE: OpenSSL PKCS #7 supports AES & SHA-2 ?
daemon@ATHENA.MIT.EDU (Whyte, William)
Thu Oct 12 09:47:50 2006
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Wed, 11 Oct 2006 04:48:25 -0400
From: "Whyte, William" <WWhyte@ntru.com>
To: "Alex Alten" <alex@alten.org>, <cryptography@metzdowd.com>
Cc: <rivest@theory.lcs.mit.edu>, <rivest@mit.edu>,
<pkcs-editor@rsasecurity.com>, <housley@vigilsec.com>,
<ekr@networkresonance.com>, <mark@awe.com>, <rse@engelschall.com>,
<shenson@drh-consultancy.demon.co.uk>, <ben@algroup.co.uk>
PKCS#7 has been superseded by the IETF's Cryptographic Message Syntax, =
CMS.
You should check within the S/MIME working group for updates.
William=20
> -----Original Message-----
> From: owner-cryptography@metzdowd.com=20
> [mailto:owner-cryptography@metzdowd.com] On Behalf Of Alex Alten
> Sent: Saturday, October 07, 2006 12:29 AM
> To: cryptography@metzdowd.com
> Cc: rivest@theory.lcs.mit.edu; rivest@mit.edu;=20
> pkcs-editor@rsasecurity.com; housley@vigilsec.com;=20
> ekr@networkresonance.com; mark@awe.com; rse@engelschall.com;=20
> shenson@drh-consultancy.demon.co.uk; ben@algroup.co.uk
> Subject: Re: OpenSSL PKCS #7 supports AES & SHA-2 ?
>=20
> After reading PKCS #1 v2 more closely and SHA-2 is not even=20
> in the specs,
> therefore OpenSSL PKCS #7 functions won't support SHA-2. =20
> This spec was
> last updated in 1998.
>=20
> PKCS Editor, is there a new update in progress by RSA Labs to=20
> incorporate
> SHA-2 and AES?
>=20
> Does OpenSSL implement PKCS #1 v2 or just v1.5? If the=20
> latter then not even
> SHA-1 is supported.
>=20
> PKCS editor, is there any timeline as to when PKCS #7 will=20
> then be updated
> with references to official OIDs, etc., for specifying SHA-2 and AES?
>=20
> Dr. Ron Rivest, are you going to publish new message-digest=20
> IETF RFCs for=20
> SHA-1
> and SHA-2? (So that they can be referenced by an updated PKCS #7.)
>=20
> Mr. Russ Housley, can you weigh in with what happening in the=20
> IETF WG security
> area? I know that Mr. Eric Rescorla is working on a new TLS v1.2=20
> draft. Will this
> be done/ratified soon? I assume OpenSSL will incorporate=20
> this soon thereafter?
>=20
> This mess with the MD5 and SHA-1 hashes is really starting to=20
> becoming a=20
> problem.
> It's certainly impacting new development projects/products=20
> I'm involved=20
> with using
> SSL and PKI certificates. My customers are concerned about=20
> using MD5 and
> SHA-1, and they don't want to keep paying for implementations=20
> repeatedly as=20
> the
> standards catch up to reality. Updating these various=20
> heavily used standards
> quickly is quite important.
>=20
> Sincerely (and thanks in advance for all of your replies),
>=20
> - Alex
>=20
>=20
> At 09:05 AM 10/6/2006 -0700, Alex Alten wrote:
> >Does anyone know if the OpenSSL PKCS #7 functions support=20
> AES and SHA-2?
> >(I assuming OpenSSL 0.9.7 or later.)
> >
> >Thanks,
> >
> >- Alex
>=20
>=20
> ---------------------------------------------------------------------
> The Cryptography Mailing List
> Unsubscribe by sending "unsubscribe cryptography" to=20
> majordomo@metzdowd.com
>=20
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com