Re: [pkix] Possible new work item: additional methods for generating key identifiers

Rene Struik <rstruik.ext@gmail.com> Mon, 23 April 2012 21:47 UTC

Return-Path: <rstruik.ext@gmail.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7445921E8041 for <pkix@ietfa.amsl.com>; Mon, 23 Apr 2012 14:47:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DGZ0nT7IS+Zy for <pkix@ietfa.amsl.com>; Mon, 23 Apr 2012 14:47:11 -0700 (PDT)
Received: from mail-gy0-f172.google.com (mail-gy0-f172.google.com [209.85.160.172]) by ietfa.amsl.com (Postfix) with ESMTP id 5A83221E8039 for <pkix@ietf.org>; Mon, 23 Apr 2012 14:47:11 -0700 (PDT)
Received: by ghbg16 with SMTP id g16so7869ghb.31 for <pkix@ietf.org>; Mon, 23 Apr 2012 14:47:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:x-enigmail-version:content-type :content-transfer-encoding; bh=mXZXoH8cDBlHQbnp/6MaplzdyTvRstIyD+OyK7K0hlc=; b=Fdx1yiLSpAqEnC7R5Sxr004QPlbb4TQGv1XqPW0hAZAMr4p5F2Ia658BSRHYYVPJa0 Vor6m8jf/yLLcKeiGUh1XtNdycBmgQqo27zJ9fV2CjR7J6DLI76eEIxWJU5qZFzCNmyv GRMhd2Yz22oGva3F9wbnGNDZcTLdnwdtGi9+OYQmrcVmHHXWl0tzvmDpIdwPCnfhav2F 4hN/a7bOTh93vQTmQgLQqrfMxoM4dpFENcE+4mCU+WHN4vj1udn8fZFcwP0OvV9jfCgw bwF6lBavtiQO9BGKC6y/DP+AGBKc1YHggtzmijqvvKCLYXIq0jDQP4EbWJYmel/Isq5N 7msA==
Received: by 10.50.203.74 with SMTP id ko10mr7882866igc.7.1335217630714; Mon, 23 Apr 2012 14:47:10 -0700 (PDT)
Received: from [192.168.1.101] (CPE0013100e2c51-CM001cea35caa6.cpe.net.cable.rogers.com. [72.138.34.10]) by mx.google.com with ESMTPS id k8sm28572847igz.4.2012.04.23.14.47.08 (version=TLSv1/SSLv3 cipher=OTHER); Mon, 23 Apr 2012 14:47:09 -0700 (PDT)
Message-ID: <4F95CDCE.4080109@gmail.com>
Date: Mon, 23 Apr 2012 17:46:54 -0400
From: Rene Struik <rstruik.ext@gmail.com>
User-Agent: Mozilla/5.0 (Windows NT 6.0; WOW64; rv:11.0) Gecko/20120327 Thunderbird/11.0.1
MIME-Version: 1.0
To: Sean Turner <turners@ieca.com>
References: <4C18DCF2.2030703@ieca.com> <4F95BB92.6080206@ieca.com>
In-Reply-To: <4F95BB92.6080206@ieca.com>
X-Enigmail-Version: 1.4.1
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Cc: pkix@ietf.org
Subject: Re: [pkix] Possible new work item: additional methods for generating key identifiers
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Apr 2012 21:47:12 -0000

Hi Sean:

You defined the key identifier to be the hash of the public key,
truncated to 160 bits. Shouldn't one have different key identifiers if
the policy fields assoicated with the public key are different (e.g., if
the same public key Qa associated with some entity A gets rolled over
and assigned a new validity period)? Similarly, shouldn't one include
the unique id of the presumed key holder (e.g.,so as to preclude people
cloning a public/private key pair to another device [I am sure
implementers contemplating this exist] without notice)?

Best regards, Rene

On 23/04/2012 4:29 PM, Sean Turner wrote:
> <no hat>
>
> I've resurrected this draft after making some changes/additions to it
> based on mailing list comments. The latest version can be found at:
>
> http://datatracker.ietf.org/doc/draft-turner-additional-methods-4kis/
>
> I'd like to ask the WG (again) to consider adopting this a WG item.
>
> spt
>
> </no hat>
>
> On 6/16/10 10:17 AM, Sean Turner wrote:
>> Greetings. Steve and I have whipped up a short I-D that specifies
>> additional methods for generating key identifiers from a public key. The
>> draft can be found at:
>>
>> http://datatracker.ietf.org/doc/draft-turner-additional-methods-4kis/
>>
>> I'd like to ask the WG to consider adopting this as a WG item.
>>
>> Cheers,
>>
>> spt*
>>
>> * (with no hat on)
>> _______________________________________________
>> pkix mailing list
>> pkix@ietf.org
>> https://www.ietf.org/mailman/listinfo/pkix
>>
> _______________________________________________
> pkix mailing list
> pkix@ietf.org
> https://www.ietf.org/mailman/listinfo/pkix


-- 
email: rstruik.ext@gmail.com
Skype: rstruik
cell: +1 (647) 867-5658
USA Google voice: +1 (415) 690-7363