Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-04-15 Thread Tomas Gustavsson via Servercert-wg
Thank you. I like the updated text, very clear for me. Regards, Tomas From: Wayne Thayer Sent: Tuesday, April 16, 2024 2:15:44 AM To: Tomas Gustavsson Cc: CA/B Forum Server Certificate WG Public Discussion List ; Clint Wilson Subject: Re: [Servercert-wg]

Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-04-13 Thread Tomas Gustavsson via Servercert-wg
Parts feel a bit redundant and confusing to me. As 6.1.5 specifies key types and sizes. An EC key pair with 184 bits should never make it to this check since only NIST P-256, NIST P-384 or NIST P-521 are allowed. No other key types than RSA and EC are allowed so what are "all other key types"?