RE: SHA1-WITH-DSA SignedData
"Pawling, John" <[email protected]> Tue, 31 Aug 1999 18:18:49 -0400
| Newsgroups | gmane.ietf.smime-examples |
|---|---|
| Message-ID | <33BD629222C0D211B6DB0060085ACF31360B32@WFHQEX03> |
All, Please ignore the test message that I sent in the attached message. I just realized that the SignedData object that we created includes the PAA (i.e. root) cert obtained from the Fortezza Card used to sign the SignedData object. The PAA cert on the card is a kludge v1 MISSI cert. I believe that we can get an equivalent v3 PAA cert that is properly encoded. There is also a negative INTEGER R value in the SignedData signature value. Once we correct the problems in the message, we will send a new one. Paul: Here is one of those erroneous messages that you were looking for:) Sorry for any inconvenience that this may have caused, - John Pawling -----Original Message----- From: Pawling, John Sent: Thursday, August 26, 1999 5:38 PM To: '[email protected]' Subject: SHA1-WITH-DSA SignedData All, Attached is a signedData object (MIME wrapped (.eml) and just ASN.1 encoded (.out)) produced using the S/MIME Freeware Library. The signedData was hashed using SHA-1 and signed using DSA. It includes a variety of signed attributes. It includes the complete cert path for the signer. The cert path includes the self-signed root (i.e. PAA) certificate which contains the DSA parameters. As stated in RFC 2459, if the DSA parameters are absent from a subject's cert, then the DSA parameters of the issuer's cert are used in conjunction with the subject's public DSA key to verify signatures signed using the subject's private DSA key (i.e. the subject inherits the parameters of the issuer). You can use the signer's DSA public key from the signer's certificate in conjunction with the DSA parameters from the PAA cert to verify the signature of the attached signedData object. We don't normally include the self-signed root in signedData objects that we produce, but it is included here for convenience of the testing. An extra cert (Key Exchange Algorithm) is also included in the signedData. More test messages will follow. ============================================ John Pawling, Director - Systems Engineering J.G. Van Dyke & Associates, Inc., a Wang Government Services Company [email protected] ============================================