[55354] in cryptography@c2.net mail archive
target collisions and colliding certificates with different identities
daemon@ATHENA.MIT.EDU (Weger, B.M.M. de)
Mon Oct 23 19:45:49 2006
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Mon, 23 Oct 2006 23:58:21 +0200
From: "Weger, B.M.M. de" <b.m.m.d.weger@TUE.nl>
To: <cryptography@metzdowd.com>, <cfrg@ietf.org>,
<hash-forum@nist.gov>
Hi all,
We announce:
- an example of a target collision for MD5; this means:=20
for two chosen messages m1 and m2 we have constructed=20
appendages b1 and b2 to make the messages collide=20
under MD5, i.e. MD5(m1||b1) =3D MD5(m2||b2);
said differently: we can cause an MD5 collision for=20
any pair of distinct IHVs;
- an example of a pair of valid, unsuspicious X.509=20
certificates with distinct Distinguished Name fields,=20
but identical CA signatures; this example makes use=20
of the target collision.
See http://www.win.tue.nl/hashclash/TargetCollidingCertificates/,
where the certificates and a more detailed announcement=20
can be found.
Marc Stevens
Arjen Lenstra
Benne de Weger
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com