3 ms·
It's the hash of the certificate that is signed by a CA. Create a certificate with the same hash and you can transplant the signature. http://web.archive.org/we
by Rafert 10y ago
It's the hash of the certificate that is signed by a CA. Create a certificate with the same hash and you can transplant the signature. http://web.archive.org/web/20071226014140/http://www.cits.rub.de/MD5Collisions/ http://web.archive.org/web/20071226014140/http://www.cits.ru... demonstrates this with the MD5 hashes of two different PDF files, a letter of recommendation and a security clearance.
It's common to sign hashes instead of the data, reasons are explained here: http://crypto.stackexchange.com/questions/12768/why-hash-the-message-before-signing-it-with-rsa http://crypto.stackexchange.com/questions/12768/why-hash-the...
- Cyph0n 10y agoSo basically it's used to verify a MAC? What I'm imagining: CA takes the hash of the certificate, encrypts that with its private key, and appends it to the cert. Client's browser then takes hash of locally stored certificate, and uses the CA's public key to check that the MAC attached to the incoming cert is valid. I'm guessing SSL uses RSA-PSS[1] or something similar. Guess I'll have to do some reading when I find the time. [1]: http://www.onefs.com/emc-plus/rsa-labs/historical/raising-standard-rsa-signatures-rsa-pss.htm http://www.onefs.com/emc-plus/rsa-labs/historical/raising-st...
- iancarroll 10y agoCertificates have a "tbsCertificate" component which holds almost everything (issuer, expiry, distinguished name, etc) except for the signature. The CA takes HashAlgo(tbsCertificate) and signs it with its issuing key. The relying party can then take HashAlgo(tbsCertificate) and see if the CA signed that value. Make sure you do not confuse encryption with signing. The hash is not private, so you do not need to hide its contents. I'm not sure if you can call it a MAC, because there is no key involved. It provides integrity guarantees, but the hash itself does not provide any authenticity guarantees; only the signed hash does.
- Cyph0n 10y agoAwesome. Thanks for the clear explanation!