[openpgp] Re: text vs. binary in an OpenPGP "Signed Mess age"

Andrew Gallagher <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On 3 Mar 2025, at 09:49, Justus Winter <[email protected]> wrote:
> 
> - If we compute/verify a text signature, we transform the data stream on
>  the fly for hashing purposes, but the downstream consumer gets the
>  data as is.
> 
> In short, if you use Sequoia, what bytes go in come out again,
> unvalidated and unchanged.
> 
>> - If not, should a verifier that encounters (d) attempt to apply CRLF
>>  line endings to the LITb?
> 
> No.

We need to be careful to distinguish between canonicalisation of the signature subject (i.e. the data on the wire that a receiver can read directly) and of the “type-specific data” that is passed into the signature hash function. The point of type 1 signatures is that the type-specific data is independent of which newline convention (if any) has been applied to the subject. So for the above question, perhaps we should clarify that the wire format of the subject SHOULD NOT be altered by the receiving implementation, but the type-specific data passed to the signature verification MUST still be normalised.

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmfFh+gACgkQXB7EBNWQ
ZimpNw/7BjOIKdHntVLZlYCvCJxcO1nwmDKS30AXsODpq3i/l63mGvFNe4vvn4rN
FF0Ss1ehsHMQ/G5aZrJV9BjAxWuH7gH227rlDg0Unu42c2x7QybvHQXSRgmGgSN8
mdSfZkV+GcmAgWCqr3kLNAJZZuN7YFvgCnkrUHpknxIMPJ6TXtiZ0gqXlj4xT9d3
+FDu4Qv/6/aI2ZLaanZZ3VgfakDbRlWPmYVY+VR51HSnF7LSdAQVTOVrk8g696Zw
Ab+Hm5o8MsHOb2Sk5kdrJQIADmOnsgrV1QESPilXqPJN3Y6U5TdpoTEqe8AXzBwE
oceH8CPSmNFwU2I4I/2O2KvYxHOyiRL3/rEz2mQ/v6ojhaKyQ+V16mdCN6TkywMF
lizhza1lHI+ga7fJgBVzqtWFbccbXUh+jnJfP/zvN+QNeuDGA502U3YSqeu45Mio
CR55NiN1N2hd+o3V4sBm45GrkI12h5jTlB22VfUyESLq/3nagkwAFFhn1D4aYIhp
S8aPttZAy8DUZLJx/vohxubP5s8oh7BOLO/EcAL7fXz2yxrX5tS5DGPF44BV6Vnp
qu7mI9IcBIofO15Ymkma5+E50cRUrQAByvTgMtj1EQV/8s9IJ1zcVcvCSxYo0BE2
zlqSrcE8NiARMSXkwGqyCxPbT5r7geXl0uh6wpFYEvMTfukedhU=
=T2U6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.