[55354] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

target collisions and colliding certificates with different identities

daemon@ATHENA.MIT.EDU (Weger, B.M.M. de)
Mon Oct 23 19:45:49 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Mon, 23 Oct 2006 23:58:21 +0200
From: "Weger, B.M.M. de" <b.m.m.d.weger@TUE.nl>
To: <cryptography@metzdowd.com>, <cfrg@ietf.org>,
	<hash-forum@nist.gov>

Hi all,

We announce:
- an example of a target collision for MD5; this means:=20
  for two chosen messages m1 and m2 we have constructed=20
  appendages b1 and b2 to make the messages collide=20
  under MD5, i.e. MD5(m1||b1) =3D MD5(m2||b2);
  said differently: we can cause an MD5 collision for=20
  any pair of distinct IHVs;
- an example of a pair of valid, unsuspicious X.509=20
  certificates with distinct Distinguished Name fields,=20
  but identical CA signatures; this example makes use=20
  of the target collision.

See http://www.win.tue.nl/hashclash/TargetCollidingCertificates/,
where the certificates and a more detailed announcement=20
can be found.

Marc Stevens
Arjen Lenstra
Benne de Weger

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post