[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Certificate requests for encryption keys



Stephen Kent wrote:
> 
> Ben,
> 
> >
> >??? If I HMAC then DH the result, isn't that a signature?
> 
> No, encrypting a hash (I assumed you meant a hash, not HMAC)

Sorry, yes, I do, of course.

> for
> verification by a specified entity (the entity whose public key was an
> input to the DH computation you performed) isn't a signature.

I encrypt the hash with my private key, of course, not someone else's
public key.

Cheers,

Ben.

--
http://www.apache-ssl.org/ben.html

"My grandfather once told me that there are two kinds of people: those
who work and those who take the credit. He told me to try to be in the
first group; there was less competition there."
     - Indira Gandhi