RE: SHA1-WITH-DSA SignedData

"Pawling, John" <[email protected]> Tue, 31 Aug 1999 18:18:49 -0400
Newsgroups gmane.ietf.smime-examples
Message-ID <33BD629222C0D211B6DB0060085ACF31360B32@WFHQEX03>
All,

Please ignore the test message that I sent in the attached message.  I just
realized that the SignedData object that we created includes the PAA (i.e.
root) cert obtained from the Fortezza Card used to sign the SignedData
object.  The PAA cert on the card is a kludge v1 MISSI cert.  I believe that
we can get an equivalent v3 PAA cert that is properly encoded.  There is
also a negative INTEGER R value in the SignedData signature value.  Once we
correct the problems in the message, we will send a new one.

Paul: Here is one of those erroneous messages that you were looking for:)

Sorry for any inconvenience that this may have caused,
- John Pawling

-----Original Message-----
From: Pawling, John 
Sent: Thursday, August 26, 1999 5:38 PM
To: '[email protected]'
Subject: SHA1-WITH-DSA SignedData


All,

Attached is a signedData object (MIME wrapped (.eml) and just ASN.1 encoded
(.out)) produced using the S/MIME Freeware Library.  The signedData was
hashed using SHA-1 and signed using DSA. It includes a variety of signed
attributes.  It includes the complete cert path for the signer.  The cert
path includes the self-signed root (i.e. PAA) certificate which contains the
DSA parameters.  As stated in RFC 2459, if the DSA parameters are absent
from a subject's cert, then the DSA parameters of the issuer's cert are used
in conjunction with the subject's public DSA key to verify signatures signed
using the subject's private DSA key (i.e. the subject inherits the
parameters of the issuer).  You can use the signer's DSA public key from the
signer's certificate in conjunction with the DSA parameters from the PAA
cert to verify the signature of the attached signedData object.  We don't
normally include the self-signed root in signedData objects that we produce,
but it is included here for convenience of the testing.  An extra cert (Key
Exchange Algorithm) is also included in the signedData.  More test messages
will follow.

============================================
John Pawling, Director - Systems Engineering
J.G. Van Dyke & Associates, Inc.,
a Wang Government Services Company
[email protected]
============================================