Re: OT: SSL certificate chain problems

2007-01-26 Thread Peter Gutmann
Victor Duchovni [EMAIL PROTECTED] writes: Generally it is enough for a TLS server or client to present its own certificate and all *intermediate* CA certificates, sending the root CA cert is optional, because if the verifying system trusts the root CA in question, it has a local copy of that root

Re: more on NIST hash competition

2007-01-26 Thread Paul Hoffman
At 9:30 PM +1300 1/25/07, Peter Gutmann wrote: =?UTF-8?B?SXZhbiBLcnN0acSH?= [EMAIL PROTECTED] writes: Perry E. Metzger wrote: http://www.csrc.nist.gov/pki/HashWorkshop/index.html I'm completely unfamiliar with the way NIST operates, but I've been wondering for years why they haven't

Re: OT: SSL certificate chain problems

2007-01-26 Thread Victor Duchovni
On Fri, Jan 26, 2007 at 07:06:00PM +1300, Peter Gutmann wrote: Victor Duchovni [EMAIL PROTECTED] writes: Generally it is enough for a TLS server or client to present its own certificate and all *intermediate* CA certificates, sending the root CA cert is optional, because if the verifying

Intuitive cryptography that's also practical and secure.

2007-01-26 Thread Matt Blaze
I was surprised to discover that one of James Randi's million dollar paranormal challenges is protected by a surprisingly weak (dictionary- based) commitment scheme that is easily reversed and that suffers from collisions. For details, see my blog entry about it: