4 ms·
No, that's the whole point of public key cryptography; that the private key cannot feasibly be used to derive the public key, but the other way around is trivia
by graphene 13y ago
No, that's the whole point of public key cryptography; that the private key cannot feasibly be used to derive the public key, but the other way around is trivial.
- Anderkent 13y ago>the private key cannot feasibly be used to derive the public key, but the other way around is trivial I assume you meant to say that the private key cannot feasibly be derived from the public key, but the other way around is trivial.
- graphene 13y agoYes, you're absolutely right; it seems it's too late to edit my original post though...
- sergiosgc 13y agoUsually, the keys are entirely symmetrical. You just name one public and the other private. It's difficult to generate one from the other. The easy task is generating both at the same time.
- skeletonjelly 13y agoCan't you generate a public key from a private one easily?
- gbaygon 13y agoYes: ssh-keygen -y -f private_key.pem > public_key.pub
- emmelaich 13y agoYes and no. It extracts the public key from the private key file. The "private" key file includes both keys. The public key file doesn't.
- dlitz 13y ago> The "private" key file includes both keys. It wouldn't need to, though. Given the private key (n,d), the public key is probably (n,65537).
- darkarmani 13y agoThe private key is normally stored in a file containing both the private and public key.
- dlitz 13y ago> Usually, the keys are entirely symmetrical. You just name one public and the other private. Nice try, General Alexander. :P In DSA, the public key is (p,q,g,y) and the private key is (p,q,g,x). The public "y" is computed directly from the private key using the formula: y = g^x mod p. Thus, anyone who has the private key can compute the public key. In RSA, the public key is (n,e) and the private key is (n,d). They're not interchangeable because of two speedups that we use: 1. Small public exponents. Most of the time, e is either 65537, 5, or 3. This speeds up encryption and signature verification, but also means you can trivially guess the public key. 2. CRT exponentiation. The private key is actually (n,d,p), where p is one of the prime factors of n. This speeds up decryption and signature verification, but recall that the security of RSA is based upon the difficulty of factoring n.