pem-dev
[Top] [All Lists]

Re: A small cloud with a golden lining?

1993-10-08 07:11:00
Since I know the public key used to sign a message, I can generate a new
certificate that has that public key. I just copy over the MIC and the
message body intact and thats it...

And no validator should place any reliance on that rogue certificate
unless it's signed with the private key of a CA whose public key can
be resolved, through a trustworthy certification path, to a (P)CA whose
public key the validator already holds.  Caveat receptor.

--jl



<Prev in Thread] Current Thread [Next in Thread>