View Issue Details

IDProjectCategoryView StatusLast Update
001008110000-007: ProfilesSpecpublic2025-01-14 16:56
ReporterBernd Edlinger Assigned ToRandy Armstrong  
Status assignedResolutionopen 
Summary0010081: wrong key length for nistP521

In the profile reporting under [CertificateKeyAlgorithm_ECC-nistP384]

I see this:
"The P-384 or P-521 curve described in
ECC public key compression is not used.
ECC coordinates are encoded as big-endian integers padded with zeros.
Signatures and keys are 96 bytes or 128 bytes."

But it is complete nonsense to say that Signatures or keys of nistP521 are 128 Bytes,
because they are (521+7)/8 * 2 = 132 raw bytes.
However it is completely misleading to point that out, because the ECC_nistP384 protocol
is not expected to use raw ECDSA signatures, or ephemeral keys of that type,
if they are used those are DER-encoded signatures embedded in a certificate.

TagsNo tags attached.
Commit Version
Fix Due Date


There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2024-12-12 14:30 Bernd Edlinger New Issue
2025-01-14 16:55 Jim Luth Assigned To => Randy Armstrong
2025-01-14 16:55 Jim Luth Status new => assigned
2025-01-14 16:56 Jim Luth Priority normal => high
2025-01-14 16:56 Jim Luth Severity minor => major