[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: key usage - key encipherment or data encipherment




Simon:

If they are encrypting the XML data directly with the RSA key (which is very unlikely), then they are correct.

The traditional way to handle this is to generate a random content-encryption key (CEK) and then encrypt the XML data with a symmetric algorithm using the CEK. The CEK is encrypted with the RSA key from the certificate. Thus, the RSA key is really being used to encrypt only symmetric keys.

Russ

 At 08:33 PM 5/10/2005, Simon McMahon wrote:

Hi,

I have had a recent interoperability issue with a application vendor that didn't like the key-usage attributes in a cert from a CA vendor's certificate. Signing certs work fine, it was an encryption cert that failed.

CA sets key-usage = "key encipherment".
Application wants to encrypt some XML data so looks for key-usage = "data encipherment". Reason - because XML is data, not a key.

I believe the application vendor is wrong and I explained that the RSA key actually encrypts an AES key so it doesn't directly encrypt the data but they want an official "pkix" ruling based on the standard so can someone please refer me to a statement in the standard that clears this up.

Thanks,

Simon McMahon.



Simon McMahon

Work: (07) 31311420
Mobile: (043) 2294180



Simon McMahon

Work: (07) 31311420
Mobile: (043) 2294180




***********************************************************************************
This email, including any attachments sent with it, is confidential and for the sole use of the intended recipient(s). This confidentiality is not waived or lost, if you receive it and you are not the intended recipient(s), or if it is transmitted/received in error.

Any unauthorised use, alteration, disclosure, distribution or review of this email is prohibited. It may be subject to a statutory duty of confidentiality if it relates to health service matters.

If you are not the intended recipient(s), or if you have received this email in error, you are asked to immediately notify the sender by telephone or by return email. You should also delete this email and destroy any hard copies produced.
***********************************************************************************