A thumbprint algorithm is another name for a hash function. No, thumbprint is not considered private. It is often encountered when talking about certificates:
The fingerprint, as displayed in the fingerprints section when looking at a certificate with firefox or the thumbprint in ie is the hash of the entire certificate. 2 looking at a potential solution where the thumbprint of a client cert is used to identify individual users and provide access control. The thumbprint is a hash value computed over the complete certificate, which includes all its fields, including the signature.
In no case does the thumbprint have anything to do with the encryption or decryption, except that some software, particularly if designed. So a few weeks ago i came across a security report that stated that the sha1 thumbprint of the certificate was a vulnerability. Both my private and public certificates have serial numbers, as a field when i view their properties, also when i access the. Id like to create an application which trusts certificates issued from specific cas.
The actual signature to verify that it came. My ideas is to have a list of thumbprints for ca certificates i trust. What's the difference between digital certificate's signature and fingerprint (thumbprint) ?