Re: ECDSA Private Keys

2020-01-12 Thread Stefan Mayr
Am 09.01.2020 um 21:45 schrieb Christopher Schultz: > DSA is almost never used. Nearly 100% of keys in the world are > plain-RSA or EC. I know of no CA that uses DSA for signing. So pretty > much every cert you will come across will be EC-with-RSA or > RSA-with-RSA (that's keytype-with-signature-ty

Re: ECDSA Private Keys

2020-01-12 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Peter, On 1/10/20 2:07 PM, logo wrote: > Chris and Mark, > > >> Am 09.01.2020 um 21:49 schrieb Christopher Schultz >> : >> > All, > > On 1/9/20 3:45 PM, Christopher Schultz wrote: Mark and Peter, On 1/9/20 3:36 PM, Mark Thomas wr

Re: ECDSA Private Keys

2020-01-10 Thread logo
Chris and Mark, > Am 09.01.2020 um 21:49 schrieb Christopher Schultz > : > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > On 1/9/20 3:45 PM, Christopher Schultz wrote: >> Mark and Peter, >> >> On 1/9/20 3:36 PM, Mark Thomas wrote: >>> On 09/01/2020 20:22, logo wrote: M

Re: ECDSA Private Keys

2020-01-09 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, On 1/9/20 3:45 PM, Christopher Schultz wrote: > Mark and Peter, > > On 1/9/20 3:36 PM, Mark Thomas wrote: >> On 09/01/2020 20:22, logo wrote: >>> Mark, >>> Am 09.01.2020 um 20:36 schrieb Mark Thomas : On 02/01/2020 09:24,

Re: ECDSA Private Keys

2020-01-09 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Mark and Peter, On 1/9/20 3:36 PM, Mark Thomas wrote: > On 09/01/2020 20:22, logo wrote: >> Mark, >> >>> Am 09.01.2020 um 20:36 schrieb Mark Thomas : >>> >>> On 02/01/2020 09:24, logo wrote: >>> >>> >>> The connector comes up correctly, is

Re: ECDSA Private Keys

2020-01-09 Thread Mark Thomas
On 09/01/2020 20:22, logo wrote: > Mark, > >> Am 09.01.2020 um 20:36 schrieb Mark Thomas : >> >> On 02/01/2020 09:24, logo wrote: >> >> >> >>> The connector comes up correctly, is accessible through the browser but if >>> I test the ssl setup, I get an error message that the key/cert may not be

Re: ECDSA Private Keys

2020-01-09 Thread Mark Thomas
On 02/01/2020 09:24, logo wrote: > Testing 370 ciphers via OpenSSL plus sockets against the server, ordered by > encryption strength I've been through these and this is the summary of the results. I'm testing OpenSSL master (although not updated for a while) and JSSE from AdoptOpenJDK 1.8.0_

Re: ECDSA Private Keys

2020-01-09 Thread logo
Mark, > Am 09.01.2020 um 20:36 schrieb Mark Thomas : > > On 02/01/2020 09:24, logo wrote: > > > >> The connector comes up correctly, is accessible through the browser but if I >> test the ssl setup, I get an error message that the key/cert may not be used >> for "Key agreement" >> >> See: >

Re: ECDSA Private Keys

2020-01-09 Thread Mark Thomas
On 02/01/2020 09:24, logo wrote: > The connector comes up correctly, is accessible through the browser but if I > test the ssl setup, I get an error message that the key/cert may not be used > for "Key agreement" > > See: > testssl.sh :8443 > > Signature Algorithm ECDSA with SHA256

Re: ECDSA Private Keys

2020-01-09 Thread Mark Thomas
On 08/01/2020 21:39, logo wrote: >> I have confirmed that this updated key then works cleanly with both the >> OpenSSL and JSSE TLS implementations. >> > > Felix already suggested that. I've tried it and at first it looks good. > Connector starts and serves the ECDSA cert. Sorry I missed that

Re: ECDSA Private Keys

2020-01-08 Thread logo
Hi Mark, > Am 08.01.2020 um 19:04 schrieb Mark Thomas : > > On 26/12/2019 23:55, logo wrote: > > > >> as an EC certificate will start with EC PRIVATE KEY. >> >> Is this something that is expected? ECDSA unsupported? Or just an incomplete >> implementation, edge case or a bug? > > Hi, > > S

Re: ECDSA Private Keys

2020-01-08 Thread Mark Thomas
On 26/12/2019 23:55, logo wrote: > as an EC certificate will start with EC PRIVATE KEY. > > Is this something that is expected? ECDSA unsupported? Or just an incomplete > implementation, edge case or a bug? Hi, Sorry for not getting to this sooner. I'm not 100% sure that Java directly suppo

Re: ECDSA Private Keys

2020-01-02 Thread logo
> Am 02.01.2020 um 17:13 schrieb Christopher Schultz > : > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Peter, > > On 1/2/20 04:24, logo wrote: > >> There may be an issue with the provided/available ciphers! >> >> The connector comes up correctly, is accessible through the brows

Re: ECDSA Private Keys

2020-01-02 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Peter, On 1/2/20 04:24, logo wrote: > There may be an issue with the provided/available ciphers! > > The connector comes up correctly, is accessible through the browser > but if I test the ssl setup, I get an error message that the > key/cert may

Re: ECDSA Private Keys

2020-01-02 Thread logo
Felix, > Am 01.01.2020 um 20:27 schrieb Felix Schumacher > : > >  >> Am 01.01.20 um 18:19 schrieb logo: >> Felix, >> Am 01.01.2020 um 11:49 schrieb Felix Schumacher : >>> >>> >>> Am 27.12.19 um 17:36 schrieb logo: Chris Am 2019-12-27 16:33, schrieb Christopher Sch

Re: ECDSA Private Keys

2020-01-01 Thread Felix Schumacher
Am 01.01.20 um 18:19 schrieb logo: > Felix, > >> Am 01.01.2020 um 11:49 schrieb Felix Schumacher >> : >> >> >> Am 27.12.19 um 17:36 schrieb logo: >>> Chris >>> >>> Am 2019-12-27 16:33, schrieb Christopher Schultz: >>> Peter, >>> >>> On 12/26/19 18:55, logo wrote: >> Hi Mark, >>> I hope it's

Re: ECDSA Private Keys

2020-01-01 Thread logo
Felix, > Am 01.01.2020 um 11:49 schrieb Felix Schumacher > : > > > Am 27.12.19 um 17:36 schrieb logo: >> Chris >> >> Am 2019-12-27 16:33, schrieb Christopher Schultz: >> Peter, >> >> On 12/26/19 18:55, logo wrote: > Hi Mark, >> >> I hope it's okay if I reply. :) >> >>> :-) >> >> >> >

Re: ECDSA Private Keys

2020-01-01 Thread Felix Schumacher
Am 27.12.19 um 17:36 schrieb logo: > Chris > > Am 2019-12-27 16:33, schrieb Christopher Schultz: > Peter, > > On 12/26/19 18:55, logo wrote: > >>> Hi Mark, > > I hope it's okay if I reply. :) > > > :-) > > > > >>> I just recently tested Step CA (smallstep.com) as an internal CA > >>> that provide

Re: ECDSA Private Keys

2019-12-27 Thread logo
Chris Am 2019-12-27 16:33, schrieb Christopher Schultz: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Peter, On 12/26/19 18:55, logo wrote: Hi Mark, I hope it's okay if I reply. :) :-) I just recently tested Step CA (smallstep.com) as an internal CA that provides an internal ACME s

Re: ECDSA Private Keys

2019-12-27 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Peter, On 12/26/19 18:55, logo wrote: > Hi Mark, I hope it's okay if I reply. :) > I just recently tested Step CA (smallstep.com) as an internal CA > that provides an internal ACME service. > > After I deployed the created cert to my Tomcat (8.5.

ECDSA Private Keys

2019-12-26 Thread logo
Hi Mark, I just recently tested Step CA (smallstep.com) as an internal CA that provides an internal ACME service. After I deployed the created cert to my Tomcat (8.5.50 with adoptopenjdk 11) I noticed that while the openssl connector immediately started, the JSSE connector with the same cert