Re: New test TSA available

tho <tho@andxor.com> Tue, 21 August 2001 11:06 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA04189 for <pkix-archive@odin.ietf.org>; Tue, 21 Aug 2001 07:06:53 -0400 (EDT)
Received: from localhost (localhost [[UNIX: localhost]]) by above.proper.com (8.11.3/8.11.3) id f7LABpJ14764 for ietf-pkix-bks; Tue, 21 Aug 2001 03:11:51 -0700 (PDT)
Received: from firewall.andxor.it (firewall.andxor.it [195.223.2.2]) by above.proper.com (8.11.3/8.11.3) with ESMTP id f7LABkN14760 for <ietf-pkix@imc.org>; Tue, 21 Aug 2001 03:11:47 -0700 (PDT)
Received: from tho.andxor.com (tho.andxor.it [195.223.2.222]) by firewall.andxor.it (8.9.2/8.9.2) with ESMTP id MAA01789; Tue, 21 Aug 2001 12:11:44 +0200 (CEST) (envelope-from tho@tho.andxor.com)
Received: (from tho@localhost) by tho.andxor.com (8.9.3/8.9.3) id MAA21240; Tue, 21 Aug 2001 12:12:26 +0200 (CEST) (envelope-from tho)
Date: Tue, 21 Aug 2001 12:12:26 +0200
From: tho <tho@andxor.com>
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>
Cc: ietf-pkix@imc.org, r.galli@com-and.com
Subject: Re: New test TSA available
Message-ID: <20010821121226.A21103@tho.andxor.com>
References: <200108210015.MAA256633@ruru.cs.auckland.ac.nz>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
User-Agent: Mutt/1.2i
In-Reply-To: <200108210015.MAA256633@ruru.cs.auckland.ac.nz>; from pgut001@cs.auckland.ac.nz on Tue, Aug 21, 2001 at 12:15:35PM +1200
X-Operating-System: FreeBSD
Sender: owner-ietf-pkix@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pkix/mail-archive/>
List-ID: <ietf-pkix.imc.org>
List-Unsubscribe: <mailto:ietf-pkix-request@imc.org?body=unsubscribe>
List-ID: <ietf-pkix.imc.org>

hello peter,

i've tried a couple of requests to cryptoapps tsa and this is what i've
found: 


::content type::

 (A) draft-ietf-pkix-time-stamp-15 states that eContentType for a time
     stamping token should be id-ct-TSTInfo why is it instead set to
     id-data ?

 since the encapsulated content type is set to id-data, version
 field in SignedData is (`correctly' since (A)) set to 1 and not to 3

::signed attributes::

 draft-ietf-pkix-time-stamp-15 states that The certificate identifier
 (ESSCertID) of the TSA certificate MUST be included as a signerInfo
 attribute inside a SigningCertificate attribute, and here it is missing

 since (A) ContentType attribute in signedAttrs inside SignerInfo is set
 to id-data

::signature algorithm::

 signatureAlgorithm in SignerInfo is rsaEncryption, shouldn't it be more
 likely sha1withRSAEncryption ?


thank you, tho
--
(__)         
(oo)        
 \/-------\
  ||     | \  
  ||---W||  *