ECDSA testing on staging


Continuing the discussion from Elliptic Curve Cryptography (ECC) Support:

Could you provide the series of commands you’re using to reproduce? Thanks!

Elliptic Curve Cryptography (ECC) Support


osiris@server custom $ openssl ecparam -genkey -name secp384r1 > privkey-p384.pem
osiris@server custom $ openssl req -new -sha256 -key privkey-p384.pem -subj "/" -reqexts SAN -config <(cat /etc/ssl/openssl.cnf <(printf "[SAN]\")) -outform der -out csr-p384.der
osiris@server custom $ letsencrypt certonly --text -vv --agree-tos --test-cert --email ${email} --csr /etc/letsencrypt/custom/csr-p384.der --webroot --webroot-map '{"": "/var/www/vhosts/"}'

Same goes for all other curves, just chose another one from openssl ecparam -list_curves in the first command :wink:

I don’t know if the complete error log for the unmarshall error is very helpful? The error is raised in _check_response in /acme/ (line 552) where it gets the HTTP 400 error response from Boulder… In exactly the same client phase of the ECDSA curve not allowed error… Guess that makes sense if you see where the unmarshall error is raised in Boulder: Just before GoodKey() :stuck_out_tongue:


Maybe i can check it with my java client tonight, but @Osiris can you provide from the debug log where the request is visible with the public key that gets rejected ?


Here you go:


Hi, i took the CSR from your debug log but no online tool where ableto decode the CSR.
Not even the ASN.1 decoder so something seems to be wrong. Also if i do an decode and rencode base64
with the default charset it did not work. My thought was an problem with maybe compressed curve points.

I will try it not for my own implementation.


Did you account for the Base64 variant used by JSON Web Signature?


Yes “Also if i do an decode and rencode base64 with the default charset it did not work.”


Just replace _ with /, - with + and don’t forget to add == for padding, because OpenSSL requires it… It’s exactly the same as the PEM CSR I fed into Let’s Encrypt :wink:


Same with my implementation independed of the ec size
ECDSA curve P-384 not allowed
ECDSA curve P-256 not allowed
ECDSA curve P-521 not allowed

So @jsha please check what happend on staging.


Very good paper of speed comparison between RSA and ECDSA for webserver with different use cases.


Too bad “Table 1: Public Key Cryptographic Operations” (and therefore the rest of the tests) doesn’t consider ECDSA public key signed with an RSA intermediate cert certificates like LE will generate :slightly_smiling:


I’ve tested with ECDSA P-256, and get the same error. It seems to me like the config change in staging hasn’t been made. Thinking about it, since the config defaults to RSA only, if there were a typo in the config there’d be no error.

The key policy used gets logged on startup, so might want to check there. @jsha


Yep, I agree the change didn’t take effect on staging, looking into it some more now.


Okay, we found the cause (a comma in the wrong place in the config), and staging should now have ECDSA properly enabled. Thanks!


Yes! It works :smiley:

osiris@server custom $ openssl x509 -noout -text <0001_cert.pem 
        Version: 3 (0x2)
        Serial Number:
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=happy hacker fake CA
            Not Before: Jan 15 23:39:00 2016 GMT
            Not After : Apr 14 23:39:00 2016 GMT
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Basic Constraints: critical
            X509v3 Subject Key Identifier: 
            X509v3 Authority Key Identifier: 

            Authority Information Access: 
                OCSP - URI:
                CA Issuers - URI:

            X509v3 Subject Alternative Name: 
            X509v3 Certificate Policies: 
                  User Notice:
                    Explicit Text: This Certificate may only be relied upon by Relying Parties and only in accordance with the Certificate Policy found at

    Signature Algorithm: sha256WithRSAEncryption
osiris@server custom $

Updated ACME from commit ebfcd90d729c39b004b1ac851a6e1a37a4c092fe to 10214e26686a362896357568bbb94b34a55a86ae and the LE client itself from 7e741f9b1acc24011de49d9f435af5b929b15a5f to 10214e26686a362896357568bbb94b34a55a86ae. :slightly_smiling: Those versions work.

secp521r1 confirmed not working (as intended by LE officials unfortunately): Invalid key in certificate request :: ECDSA curve P-521 not allowed, prime256v1 works splendidly (just as secp384r1 above) and results in “working” (happy hacker fake CA :stuck_out_tongue:) certificate.

Other curves like brainpoolP512r1 still results in an The request message was malformed :: Error unmarshaling certificate request error message from Boulder.

Any more tests I could do @jsha ? :stuck_out_tongue:

There was only one pull request with 6 commits merged since the branching off of the master branch for the 0.2.0 release, so I guess the 0.2.0 release won’t have the bug(s) I had earlier and will do fine :slightly_smiling: The 0.1.1 release… I dunno… My ACME release was from Dec 17th and the first 0.1.1 was released on the 16th… My guess is the 0.1.1 release will not work with ECDSA CSR’s.


acmetool’s ECDSA support is working nicely.

Since the staging server doesn’t have support for ECDSA account keys yet, one needs to create an RSA account key and then change the key type preference to ECDSA:

$ sudo acmetool quickstart
$ sudo acmetool quickstart --expert
$ sudo acmetool want


[quote=“Osiris, post:15, topic:8809”]
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
[/quote]RSA certificates should have both “Digital Signature” and “Key Encipherment” key usages, but ECDSA certificates should have only “Digital Signature”.

Glad it’s not production…

Problem Issuing EC-384 Certificate

Hmm, interesting… But the only source for this I can find is an (old) IETF draft: Representation of Elliptic Curve Digital Signature Algorithm (ECDSA) Keys and Signatures in Internet X.509 Public Key Infrastructure Certificates (draft-ietf-pkix-ipki-ecdsa-02.txt): Section 3.1.3 (Key Usage Extension in ECDSA certificates).

However, this draft has never reached a RFC status and is expired.

Do you have another source?


From IETF mailing list:

It mentions “key agreement”, but research have shown such bit allowing TLS server to be impersonated under certain circumstances, so it MUST NOT be set.


Would be nice to habe more Details about this point.