[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
X.509 certificate collision, via MD5 collisions
I have not had an opportunity to review this document yet, but the findings
need to be shared with the whole Internet security community.
We announce a method for the construction of pairs of valid X.509
certificates in which the "to
be signed" parts form a collision for the MD5 hash function. As a result
the issuer signatures
in the certificates will be the same when the issuer uses MD5 as its hash
function.
http://eprint.iacr.org/2005/067