Yes Paul, you are right. Real CA must never accept CSR without verifying the signature. Francesco Petruzzi Information Security Manager Innovery SpA Via Farini, 81 – 20159 Milano Cell. +39 320 170 4978 Da: Paul Yang [mailto:kaishen.yy@xxxxxxxxxx]
Dare any CA proceed to sign a CSR without verifying the signature… Maybe there are scenarios we are not aware about...
On Sep 12, 2019, at 4:41 PM, Francesco Petruzzi <francesco.petruzzi@xxxxxxxxxxxx> wrote: Sign request with a fake private key and hope the client do not require signature verification. Regards Francesco Petruzzi Da: openssl-users
[mailto:openssl-users-bounces@xxxxxxxxxxx] Per conto di Paul Yang via openssl-users How could you create the CSR with only public key? On Sep 12, 2019, at 3:50 PM, Bharathi Prasad <barati.j.prasad@xxxxxxxxx> wrote: Hi,
Paul Yang
Paul Yang |