[146577] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [Cryptography] Google's Public Key Size (was Re: NSA and

daemon@ATHENA.MIT.EDU (Phillip Hallam-Baker)
Thu Sep 5 15:17:09 2013

X-Original-To: cryptography@metzdowd.com
In-Reply-To: <CAMm53wQPd_rSwMdeqmiXGi6AR2Jvpd8fy+5m0u3Cb2XPehVtBw@mail.gmail.com>
Date: Thu, 5 Sep 2013 14:26:23 -0400
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Andy Steingruebl <steingra@gmail.com>
Cc: "cryptography@metzdowd.com List" <cryptography@metzdowd.com>,
	Paul Hoffman <paul.hoffman@vpnc.org>
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com

--===============5472469048463512318==
Content-Type: multipart/alternative; boundary=001a11c264a431536304e5a70f08

--001a11c264a431536304e5a70f08
Content-Type: text/plain; charset=ISO-8859-1

On Wed, Sep 4, 2013 at 6:58 PM, Andy Steingruebl <steingra@gmail.com> wrote:

> On Wed, Sep 4, 2013 at 3:54 PM, Paul Hoffman <paul.hoffman@vpnc.org>wrote:
>
>> On Sep 4, 2013, at 2:15 PM, Andy Steingruebl <steingra@gmail.com> wrote:
>>
>> > As of Jan-2014 CAs are forbidden from issuing/signing anything less
>> than 2048 certs.
>>
>> For some value of "forbidden". :-)
>>
>
> This is why you're seeing Mozilla and Google implementing these checks for
> compliance with the CABF Basic Requirements in  code....
>
> - Andy
>

Which is rather easier to effect since the browser providers have no
longstanding contractual agreements made prior to the BRs being adopted.

-- 
Website: http://hallambaker.com/

--001a11c264a431536304e5a70f08
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_extra"><br><br><div class=3D"gmail_quo=
te">On Wed, Sep 4, 2013 at 6:58 PM, Andy Steingruebl <span dir=3D"ltr">&lt;=
<a href=3D"mailto:steingra@gmail.com" target=3D"_blank">steingra@gmail.com<=
/a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div class=3D"im">On Wed, S=
ep 4, 2013 at 3:54 PM, Paul Hoffman <span dir=3D"ltr">&lt;<a href=3D"mailto=
:paul.hoffman@vpnc.org" target=3D"_blank">paul.hoffman@vpnc.org</a>&gt;</sp=
an> wrote:<br>
</div><div class=3D"gmail_extra"><div class=3D"gmail_quote"><div class=3D"i=
m">
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div>On Sep 4, 2013, at 2:15 PM, Andy Steing=
ruebl &lt;<a href=3D"mailto:steingra@gmail.com" target=3D"_blank">steingra@=
gmail.com</a>&gt; wrote:<br>


<br>
&gt; As of Jan-2014 CAs are forbidden from issuing/signing anything less th=
an 2048 certs.<br>
<br>
</div>For some value of &quot;forbidden&quot;. :-)<br></blockquote><div><br=
></div></div><div>This is why you&#39;re seeing Mozilla and Google implemen=
ting these checks for compliance with the CABF Basic Requirements in =A0cod=
e....</div>
<span class=3D"HOEnZb"><font color=3D"#888888">
<div><br></div><div>- Andy</div></font></span></div></div></div></blockquot=
e><div><br></div><div>Which is rather easier to effect since the browser pr=
oviders have no longstanding contractual agreements made prior to the BRs b=
eing adopted.</div>
<div>=A0</div></div>-- <br>Website: <a href=3D"http://hallambaker.com/">htt=
p://hallambaker.com/</a><br>
</div></div>

--001a11c264a431536304e5a70f08--

--===============5472469048463512318==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography
--===============5472469048463512318==--

home help back first fref pref prev next nref lref last post