# Use of ECC Algorithms with Ciphermail?

**URL:** <https://community.ciphermail.com/t/use-of-ecc-algorithms-with-ciphermail/406>\
**Category:** Gateway\
**Created:** [October 27, 2014, 2:45pm UTC](https://community.ciphermail.com/t/use-of-ecc-algorithms-with-ciphermail/406 "2014-10-27T14:45:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [October 27, 2014, 2:45pm UTC](https://community.ciphermail.com/t/use-of-ecc-algorithms-with-ciphermail/406/1 "2014-10-27T14:45:45Z")

</div>

Hello,

just curious but i would like to know if Ciphermail latest release is  
prepared to handle ECC algorithms instead of RSA/DSA according to the  
RFC 3278/5753??

I'm totaly aware that one needs a ECC PKI chain for this, but just to  
be sure if this is fully implemented...

Regards

Andreas

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [November 3, 2014, 9:26am UTC](https://community.ciphermail.com/t/use-of-ecc-algorithms-with-ciphermail/406/2 "2014-11-03T09:26:09Z")

</div>

Bouncycastle seems to support RFC 5753 but I must admin I have not  
tested ECC certificates yet. I have done some testing with PGP ECC keys  
although support for ECC PGP keys is only supported by the beta version  
of GPG 2 so testing was not complete.

I will do some tests with ECC certificates. The biggest issue is getting  
good test cases.

Kind regards,

Martijn Brinkers

> **···**
>
> On 10/27/2014 03:45 PM, lst\_hoe02(a)kwsoft.de wrote:
> 
> > just curious but i would like to know if Ciphermail latest release is  
> > prepared to handle ECC algorithms instead of RSA/DSA according to the  
> > RFC 3278/5753??
> > 
> > I'm totaly aware that one needs a ECC PKI chain for this, but just to be  
> > sure if this is fully implemented...
> 
> --  
> CipherMail email encryption
> 
> Open source email encryption gateway with support for S/MIME, OpenPGP  
> and PDF messaging.
> 
> > **[CipherMail email encryption and digital signatures](https://www.ciphermail.com)**
> >
> > Easy to use server-side email encryption for automatic encryption and digital signing of email.
> 
> Twitter: [http://twitter.com/CipherMail](http://twitter.com/CipherMail)

---

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [November 3, 2014, 10:43am UTC](https://community.ciphermail.com/t/use-of-ecc-algorithms-with-ciphermail/406/3 "2014-11-03T10:43:17Z")

</div>

Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:

> **···**
>
> > On 10/27/2014 03:45 PM, lst\_hoe02(a)kwsoft.de wrote:
> > 
> > > just curious but i would like to know if Ciphermail latest release is  
> > > prepared to handle ECC algorithms instead of RSA/DSA according to the  
> > > RFC 3278/5753??
> > > 
> > > I'm totaly aware that one needs a ECC PKI chain for this, but just to be  
> > > sure if this is fully implemented...
> > 
> > Bouncycastle seems to support RFC 5753 but I must admin I have not  
> > tested ECC certificates yet. I have done some testing with PGP ECC keys  
> > although support for ECC PGP keys is only supported by the beta version  
> > of GPG 2 so testing was not complete.
> > 
> > I will do some tests with ECC certificates. The biggest issue is getting  
> > good test cases.
> > 
> > Kind regards,
> > 
> > Martijn Brinkers
> 
> As of certificates i found this one [http://www.entrust.net/ecc/](http://www.entrust.net/ecc/)  
> May intention was to first ask if it is useful to do some actual  
> testing or if this is known not working as of today. If i have some  
> spare time to poke around with ECC certifiactes i will let you know.
> 
> Thanks
> 
> Andreas

---

<div class="post-metadata">

**Author:** ![lst\_hoe021](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@lst\_hoe021](https://community.ciphermail.com/u/lst_hoe021)\
**Post date:** [November 3, 2014, 4:43pm UTC](https://community.ciphermail.com/t/use-of-ecc-algorithms-with-ciphermail/406/4 "2014-11-03T16:43:13Z")

</div>

Zitat von Martijn Brinkers \<martijn(a)djigzo.com\>:

> > just curious but i would like to know if Ciphermail latest release is  
> > prepared to handle ECC algorithms instead of RSA/DSA according to the  
> > RFC 3278/5753??
> > 
> > I'm totaly aware that one needs a ECC PKI chain for this, but just to be  
> > sure if this is fully implemented...
> 
> Bouncycastle seems to support RFC 5753 but I must admin I have not  
> tested ECC certificates yet. I have done some testing with PGP ECC keys  
> although support for ECC PGP keys is only supported by the beta version  
> of GPG 2 so testing was not complete.
> 
> I will do some tests with ECC certificates. The biggest issue is getting  
> good test cases.
> 
> Kind regards,
> 
> Martijn Brinkers

Ok, looks like not working as of today:

Import certificate + root-CA is ok, but this looks suspicious when  
clicking on the cert

Public Key Length  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-1

Public Key Algorithm  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Unknown

When trying to sign with this cert/key we got the following

03 Nov 2014 17:10:12 | ERROR Error signing the message.  
(mitm.application.djigzo.james.mailets.SMIMESign) [Spool Thread #2]  
mitm.common.security.smime.SMIMEBuilderException:  
org.bouncycastle.operator.OperatorCreationException: cannot create  
signer: Supplied key  
(org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPrivateKey) is not  
a RSAPrivateKey instance  
&nbsp;&nbsp;at  
mitm.common.security.smime.SMIMEBuilderImpl.addSigner(SMIMEBuilderImpl.java:264)  
&nbsp;&nbsp;at  
mitm.common.security.smime.SMIMEBuilderImpl.addSigner(SMIMEBuilderImpl.java:276)  
&nbsp;&nbsp;at  
mitm.application.djigzo.james.mailets.SMIMESign.serviceMail(SMIMESign.java:414)  
&nbsp;&nbsp;at  
mitm.application.djigzo.james.mailets.AbstractDjigzoMailet.service(AbstractDjigzoMailet.java:277)  
&nbsp;&nbsp;at  
org.apache.james.transport.LinearProcessor.service(LinearProcessor.java:424)  
&nbsp;&nbsp;at  
org.apache.james.transport.JamesSpoolManager.process(JamesSpoolManager.java:405)  
&nbsp;&nbsp;at  
org.apache.james.transport.JamesSpoolManager.run(JamesSpoolManager.java:309)  
&nbsp;&nbsp;at java.lang.Thread.run(Thread.java:745)  
Caused by: org.bouncycastle.operator.OperatorCreationException: cannot  
create signer: Supplied key  
(org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPrivateKey) is not  
a RSAPrivateKey instance  
&nbsp;&nbsp;at  
org.bouncycastle.operator.jcajce.JcaContentSignerBuilder.build(Unknown  
Source)  
&nbsp;&nbsp;at  
mitm.common.security.smime.SMIMEBuilderImpl.addSigner(SMIMEBuilderImpl.java:258)  
&nbsp;&nbsp;... 7 more  
Caused by: java.security.InvalidKeyException: Supplied key  
(org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPrivateKey) is not  
a RSAPrivateKey instance  
&nbsp;&nbsp;at  
org.bouncycastle.jcajce.provider.asymmetric.rsa.DigestSignatureSpi.engineInitSign(Unknown  
Source)  
&nbsp;&nbsp;at java.security.Signature$Delegate.engineInitSign(Signature.java:1147)  
&nbsp;&nbsp;at java.security.Signature.initSign(Signature.java:511)  
&nbsp;&nbsp;... 9 more

Thunderbird looks like at least basically working with ECC.

Regards

Andreas

> **···**
>
> > On 10/27/2014 03:45 PM, lst\_hoe02(a)kwsoft.de wrote:
