Skip to content

Latest commit

 

History

History
20 lines (18 loc) · 2.94 KB

Certificate Signature.md

File metadata and controls

20 lines (18 loc) · 2.94 KB
Certificate signature algorithm IANA TLS version ('NIST', '') 1 ('NIST', 'Condition') ('BSI', '') 2 ('BSI', 'Condition') 3 ('ANSSI', '') 4 ('MOZILLA (+AgID)', 'Modern') 5 ('MOZILLA (+AgID)', 'Intermediate') ('MOZILLA (+AgID)', 'Old')
anonymous 0 1.2 must not 6 <Not mentioned> must not 7 <Not mentioned> <Not mentioned> <Not mentioned>
rsa 8 1 1.2 must THIS or CertificateSignature ecdsa and CHECK_KEY_TYPE rsa 9 recommended THIS or CertificateSignature dsa;ecdsa AND YEAR 2025 optional <Not mentioned> <Not mentioned> <Not mentioned>
dsa 2 1.2 <Not mentioned> CHECK_KEY_TYPE dsa 10 recommended THIS or CertificateSignature rsa;ecdsa AND YEAR 2029 <Not mentioned> <Not mentioned> <Not mentioned> <Not mentioned>
ecdsa 3 1.2 must THIS or CertificateSignature rsa and CHECK_KEY_TYPE ecddsa 11 recommended THIS or CertificateSignature rsa;dsa recommended <Not mentioned> <Not mentioned> <Not mentioned>

Footnotes

  1. SP800-52 section 3.2

  2. BSI-TR-02102-2, 3.3.3 + 3.4.3

  3. Not explicitally mentioned but required to match the mechanical check of the conditions with the NIST case

  4. R8

  5. Being a list of recommendations:

    not mentioned --> not recommended

  6. TLS servers conforming to this specification shall be configured with an RSA signature certificate or an ECDSA signature certificate

  7. R8+R5

  8. We consider RSASSA-PSS as a subset of RSA (as stated in ANSSI v1.2 R8)

  9. At a minimum, TLS servers conforming to this specification shall be configured with an RSA signature certificate or an ECDSA signature certificate.

  10. recommended "if key is DH"

  11. At a minimum, TLS servers conforming to this specification shall be configured with an RSA signature certificate or an ECDSA signature certificate.