Fixed hash algorithm in CertEnroll library

Posted: 08-29-2006, 09:32 AM
Hello!

The problem is fixed hash algorithm (SHA1) used in CertEnroll library.

That's why we can't create a certificate request using our Cryptographic
Provider (CSP), that implements Russian Crypto-algorithms but not SHA1.

X509Enrollment.IX509CertificateRequestPkcs10 interface has HashAlgorithm
property that is used for signing PKCS#10. But after creating PKCS#10
CertEnroll creates "dummy-certificate" for the "Request" store (like XEnroll
does). And it tries to sign this certificate with fixed in
CertEnroll::CX509SignatureInformation::SetDefaultV alues SHA1. We think that
it is more correct to use the same hash algorithm as for signing PKCS#10.



And several comments for "Certificate Enrollment" wizard from
"Certificates" snap-in:

First of all there is similar problem. User can't choose hash algorithm for
request signing. So, there is no UI for HashAlgorithm property.



The last build of Windows Vista we looked at is 5536.





Related links are:

http://www.ietf.org/rfc/rfc4357.txt

http://www.ietf.org/rfc/rfc4357.txt

http://www.ietf.org/rfc/rfc4491.txt



P.S. If such behavior won't be corrected in release version of Vista, we
will have to resolve it in any way, this is critical for us. So, we will
request a fix for Vista using our benefits as Microsoft Gold Certified
Partner. So, we want to ask Microsoft to help us to avoid this process!



Thank you!



Roman Sedov
Crypto-Pro Company
Phone: +7(495)933-1168, +7(495)689-43-67
WWW: http://www.cryptopro.ru
e-mail: sedov@cryptopro.ru


Reply With Quote

Responses to "Fixed hash algorithm in CertEnroll library"

 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


Similar Threads
Thread Thread Starter Forum Replies Last Post
fixed router spi problems TimeZone Windows Vista Networking & Sharing 2 10-14-2006 01:07 AM
fixed router spi problem TimeZone Windows Vista Networking & Sharing 0 10-13-2006 06:33 PM
Media library sharing v-6udayt Windows Vista Networking & Sharing 1 08-21-2006 11:57 AM
My games library complete on Vista Stephen Sobchuk Windows Vista Games 0 06-29-2006 11:53 AM
Soundmax Audio Fixed Dustin Harper Windows Vista Install & Setup 1 06-13-2006 06:51 AM