RSA-OAEP vs. RSA-OAEP-MGF1P

Ian Young ian at iay.org.uk
Tue Feb 3 11:24:02 EST 2015


> On 3 Feb 2015, at 16:13, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
>> I guess I'd respond by saying that if it advertises those two algorithms -- with
>> no mask function parameters -- then if I understand what you're saying it's
>> just saying the same thing twice.
> 
> Functionally yes, but they're discrete algorithm URIs in the spec and at runtime, so saying you support one definitely doesn't imply the other.

Right, but as the MGF1P variant was MTI in 1.0 and functionally identical, there's no advantage that I can see in also saying that you support the same bundle of algorithms under another name (the unparameterised generic one). So if the size of the metadata is a concern at all you'd suppress the more general algorithm specifier unless you did want to parameterise it.

> It may not be trivial to actually get it doing that, but you can certainly file an issue.

Will do. It will not be a high priority one ;-)

    -- Ian




-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20150203/4896e01e/attachment.bin 


More information about the dev mailing list