IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: OpenSSH certified keys



--On Wednesday, March 17, 2010 04:19:28 AM +1100 Damien Miller <djm%mindrot.org@localhost> wrote:


The nonce field is a CA-provided random bitstring of arbitrary length
(but typically 16 or 32 bytes) included to make attacks that depend on
inducing collisions in the signature hash infeasible.

Except that you've put it so late in the "certificate" that it's not terribly useful for that purpose against current attacks.



Home | Main Index | Thread Index | Old Index