[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [saag] X.509 certificate collision, via MD5 collisions




At 18:58 04/03/2005, Robert Zuccherato wrote:

The reason why the randomness in the serial number is able to prevent this particular attack is that the attacker cannot predict it's value and thus cannot predict the value of the hash function chaining variable at the point the public keys begin to get processed. This appears to prevent the construction of collisions in the public keys.

This was why I suggested in TSP we removed the 'monotonic increasing' requirement for a TSA serial number during final draft. Mananaging 'random' serial numbers is not so easy but I rather think it is a requirement.

The attacks highlight the importance of making every bit significant in the message to be hashed. Aside from certificates, I've got increasingly worried about the non-rendered and/or highly redundant junk in documents. I trust logos aren't going to cause problems here.

Adrian Pickering/
University of Southampton, UK