[openpgp] Re: text vs. binary in an OpenPGP "Signed Mess age"
Justus Winter <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Daniel Huigens <[email protected]> writes: > Hi :) > > On Monday, March 3rd, 2025 at 10:49, Justus Winter wrote: >> > - If not, should a verifier that encounters (d) attempt to apply CRLF >> > line endings to the LITb? >> >> No. > > I'm confused by either the answer or the question :') > > When I answered yes, I meant, the verifier should normalize the line > endings of the contents of the literal data packet before feeding it > into the hash of the signature. > > I agree that it shouldn't affect the data returned to the application. And Andrew writes: > We need to be careful to distinguish between canonicalisation of the > signature subject (i.e. the data on the wire that a receiver can read > directly) and of the “type-specific data” that is passed into the > signature hash function. The point of type 1 signatures is that the > type-specific data is independent of which newline convention (if any) > has been applied to the subject. So for the above question, perhaps we > should clarify that the wire format of the subject SHOULD NOT be > altered by the receiving implementation, but the type-specific data > passed to the signature verification MUST still be normalised. I think we are all in agreement. Sorry if I was unclear. Best, Justus _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 584 B)
-----BEGIN PGP SIGNATURE----- wsC7BAEBCgBvBYJnxYmFCRCI3H4zOF95HUcUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmcKHSBKgCFQOgaB6IZv49U0JUOJ5v7qb7GfNtnapuxJ BRYhBCVqTlXkpy2XrSRo54jcfjM4X3kdAACNRgf9ErLoMAV+Zh9IG3NTPvavS+0x Bw+0bdzlMeoylRWsC4ZFYpodDfZX0S3jlonkZh6+tL0Zw6HK3z8/FVuhsvn6Egod MFRZWVZN1V8kkFXZD/MGvJqgYIFhfcs+3h0XqOUA+iM4glT+lGoLHc7rPxpalbG8 sKMjtqxbgfqZcjmfEkNjitz8F+AtDNRFqcrTKZeOKr8kPnqm80eQ1xBo0dvETwk1 a8KVF9l7Scq9f2GfhLcGKAHIhj4GimqFpCukc6oJ6vD7+jEaDeSyG7w8JYChP145 2PDFwO/BcbCQh22ShXpQcXFXjbkbIR+RWAETNyE7oWAU7q2pEFlwoazdLA9JkA== =DjKy -----END PGP SIGNATURE-----