comments and corrections for draft-ietf-smime-examples-06
"Life is hard, and then you die" <[email protected]> Thu, 15 Mar 2001 19:53:04 -0800
| Newsgroups | gmane.ietf.smime-examples |
|---|---|
| Message-ID | <[email protected]> |
--FL5UXtIhxfXey3p5
Content-Type: text/plain; charset=us-ascii
While decoding the examples, I found what I believe are a few bugs.
Specifically:
1) Example 6.7:
the KEKIdentifier contains a GeneralizedTime of
'951230235959Z', which not a valid GeneralizedTime - the year
must be 4 digits long, i.e. '19951230235959Z'.
2) Examples 6.4 and 6.5:
the OId for the DH key-agreement algorithm in the
KeyAgreeRecipientInfo.keyEncryptionAlgorithm field is given as
1.2.840.10046.2.1; however, rfc-2630, section 12.3.1.1 states
that the OId must be 1.2.840.113549.1.9.16.3.5 .
3) Example 7.0, DigestedData:
the content is not the ExContent.bin bytes - it's a truncated
version thereof ("This some sampe content."). The digest however
was calculated over ExContent.bin bytes, which means that the
digest doesn't verify. I'm attaching a fixed DigestedData
(7.0.bin).
4) Examples 5.1, 5.3, 5.6, 5.7, SignedData:
I'm unable to verify the signatures on these. To double check,
I've extracted the raw signature bytes and the public key and
took the ExContent.bin, and they still won't verify, so I'm
assuming the examples are at fault.
Also, a hint that the examples might be screwed is that the
signatures contain a spurious 0 byte at the end (in the case of
5.3 there are actually two of them): if you do the math on the
last octet string in the SignerInfo, you'll see that while it
always has length 48, the dsa signature within is actually only
47 bytes long (46 bytes in the case of 5.3).
5) Examples 5.4, 5.10, 11.1, 11.3, 11.4, and 11.5, SignedData:
The OId in SignerInfo.signatureAlgorithm is given as
1.2.840.10040.4.1, but instead it should be 1.2.840.10040.4.3
(the former is the *key* algorithm OId for DSA, not signature
algorithm OId).
I'm attaching fixed 5.4.bin and 5.10.bin, which I'm able to
verify the signature on - I haven't tested the 11.x series
yet.
6) Examples 5.8 and 5.9, signed mails:
These have both the above problems, i.e. wrong OId, spurious
0 byte at the end, and signature won't verify.
Interestingly, I can't verify any DSA signatures created by Jim Schaad;
those created by John Pawling I can (after fixing the OId).
7) Bob's RSA private key (BobPrivRSAEncrypt.pri) does not match the
public key in his certificate (BobRSASignByCarl.cer) - compare the
moduli and you'll see they differ. The examples 6.2 and 6.3 (haven't
checked the others yet) seem to use a private key other than the one
given (presumably the one matching the public key in the
certificate?) as I'm unable to decrypt those.
8) 6.8.eml got a bit messed up: when you decode it with the provided
perl script the LF's are missing (i.e. there are only CR's). No big
deal, though.
Lastly, would it be possible to add a couple examples of nested CMS
messages? I.e. CMS messages where the ContentType is not "Data"? (for
example EnvelopedData within SignedData and visa versa) I know these
aren't used by S/MIME, but CMS does mention that they can be used, and
unfortunately it does not say anything about what exactly goes into the
EncapsulatedContentInfo.eContent and as input for the calculation of the
EncryptedContentInfo.encryptedContent when the content type is anything
other than "Data". (I presume it's just the BER-encoded object?)
Cheers,
Ronald
--FL5UXtIhxfXey3p5
Content-Type: application/octet-stream
Content-Disposition: attachment; filename="7.0.bin"
Content-Transfer-Encoding: base64
MF4GCSqGSIb3DQEHBaBRME8CAQAwBwYFKw4DAhowKwYJKoZIhvcNAQcBoB4EHFRoaXMgaXMg
c29tZSBzYW1wbGUgY29udGVudC4EFEBq7AhSebpuFgItngYpwCKWh91I
--FL5UXtIhxfXey3p5
Content-Type: application/octet-stream
Content-Disposition: attachment; filename="5.4.bin"
Content-Transfer-Encoding: base64
MIIKpwYJKoZIhvcNAQcCoIIKmDCCCpQCAQExCTAHBgUrDgMCGjArBgkqhkiG9w0BBwGgHgQc
VGhpcyBpcyBzb21lIHNhbXBsZSBjb250ZW50LqCCB4cwggICMIIBb6ADAgECAhBGNGvHgABW
vBHTbi7EELOwMAkGBSsOAwIdBQAwEjEQMA4GA1UEAxMHQ2FybFJTQTAeFw05OTA5MTkwMTA4
NDdaFw0zOTEyMzEyMzU5NTlaMBMxETAPBgNVBAMTCEFsaWNlUlNBMIGfMA0GCSqGSIb3DQEB
AQUAA4GNADCBiQKBgQDgiXM5jdj19eiHdjl/TrAFu1OD3g+3q9x9x3UpDQUubRLfpoYm1NJv
qlgp/Jfs+oJRDzCAvrFQnkZE8Sy72DLPxmhvB9mwYKy+7jQJahP19wUFk99eujVW2WH/GX/J
geb4bOqHQHDvrG0sdJ8t+lU6uZl3AqZIUoxO81c4V3RXXwIDAQABo2AwXjAMBgNVHRMBAf8E
AjAAMA4GA1UdDwEB/wQEAwIGwDAfBgNVHSMEGDAWgBTp4JAnrHggeprTTPJCN04irp44uzAd
BgNVHQ4EFgQUd9K00bdMioqjzkWdzuw8oDrj/1AwCQYFKw4DAh0FAAOBgQC/NDLm/GqIQX3w
XJmhk7dJtwJSHsuErJPXWCsAoZzESEiZ3QLDxgX40iXxo5zJMwGKdg5vd0Ojv+Hms2oEeTnu
4enlnVAHiyLcElDj87Q9nuWTnrHNM/ngq5hxCfjrsPyc7PGI2K4D0f5g4WIUsaIj0siNGB9e
7ptyAifChT0ELjCCApswggJaoAMCAQICAQEwCQYHKoZIzjgEAzASMRAwDgYDVQQDEwdDYXJs
RFNTMB4XDTk5MDgxNjIyNTA1MFoXDTM5MTIzMTIzNTk1OVowEjEQMA4GA1UEAxMHQ2FybERT
UzCCAbcwggErBgcqhkjOOAQBMIIBHgKBgQC2SRg+ikTBKXGUTAHEEsF6ectUTasegfvGTLMO
lAkG6wHUschxS8dFwFAlXZz82uRt0+KGSISCfboVlUoW9kbt3faY0rt+igqKuhZ7uVABSJOL
6yUVUZdV3I9TDhCpUPxwt80wVP3a3qiqIrWhr4vMAojni3Bfua3hCNRtKS3W6QIVAN3BL99T
zgs0YHc+AqS/il2YuRDVAoGADO5Xm0u92rYHanQ3T1V/ne28YQ3rRlk8VgsrWwyRzqViUmnK
4W0+vb/+4be5K2E8rcuuReMGrIwinZxEhwvHzfAc2bVOXXPerw7JHVpR9U9EeTVac6p/RlEf
qUIWnEjrinlhtNUvUyJEYx+GuKNYBiX4KcDvuuB18ELEY2VSmwoDgYUAAoGBAJmHdCcDZqCx
wK3cLHW74WxEnNohbU1HbbFiCenYrh7yOrSUsaOOeptxTgCUybQlTrlglhkkAfNiDP51wPvO
2GgA4/3VcE/fI5YZBpT0sWGPOlexCBGkCyYl8FJ2geoLYg2VKuaGunKyp1CDC6onzRupTYma
140YOYQ/i8VWTYB6o0IwQDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBhjAdBgNV
HQ4EFgQUcEQ+gi5vh95K03XjPSC8QyuT8R8wCQYHKoZIzjgEAwMwADAtAhRrqfBOelp54/m+
PSvJBjfpERehEwIVAI80aSqLsTwDeZQyTRIfzon7RrI7MIIC3jCCAp2gAwIBAgICAMgwCQYH
KoZIzjgEAzASMRAwDgYDVQQDEwdDYXJsRFNTMB4XDTk5MDgxNzAxMTA0OVoXDTM5MTIzMTIz
NTk1OVowEzERMA8GA1UEAxMIQWxpY2VEU1MwggG2MIIBKwYHKoZIzjgEATCCAR4CgYEAgY3N
7YPqCp45PsJIKKPkR5PdDteoDuxTxauECE//lOFzSH4M1vNESNH+n6+koYkv4dkwyDbeP5u/
t0zcX2mK5HXQNwyRCJWb3qde+fz0ny/dQ6iLVPE/sAcIR01diMPDtbPjVQh11Tl2EMR4vf+d
sISXN/LkURu15AmWXPN+W9sCFQDiR6YaRWa4E8baj7g3IStii/eTzQKBgCY40BSJMqo5+z5t
2UtZakx2IzkEAjVc8ssaMMMeUF3dm1nizaoFPVjAe6I2uG4Hr32KQiWn9HXPSgheSz6Q+G3q
nMkhijt2FOnOLl2jB80jhbgvMAF8bUmJEYk2RL34yJVKU1a14vlz7BphNh8Rf8K97dFQ/5h0
wtGBSmA5ujY5A4GEAAKBgFzjuVp1FJYLqXrd4z+p7Kxe3L23ExE0phaJKBEj2TSGZ3V1ExI9
Q1tv5VG/+onyohs+JH09B41bY8i7RaWgSuOF1s4GgD/oI34a8iSrUxq4Jw0e7wi/ZhSAXGKs
ZfoVi/G7NNTSljf2YUeyxDKE8H5BQP1Gp2NOM/Kl4vTyg+W4o4GDMIGAMCAGA1UdEQQZMBeB
FWFsaWNlRHNzQGV4YW1wbGVzLmNvbTAMBgNVHRMBAf8EAjAAMA4GA1UdDwEB/wQEAwIGwDAf
BgNVHSMEGDAWgBRwRD6CLm+H3krTdeM9ILxDK5PxHzAdBgNVHQ4EFgQUvmyhs+PB9+1DcKTO
EwHi/eOX/s0wCQYHKoZIzjgEAwMwADAtAhUAmLDGP89xR1o1qUqPwPgkBehGlI4CFFufSMCM
ocECnETq6aGHwaV/KC27oYHbMIHYMIGZMAkGByqGSM44BAMwEjEQMA4GA1UEAxMHQ2FybERT
UxcNOTkwODI3MDcwMDAwWjBpMBMCAgDIFw05OTA4MjIwNzAwMDBaMBMCAgDJFw05OTA4MjIw
NzAwMDBaMBMCAgDTFw05OTA4MjIwNzAwMDBaMBMCAgDSFw05OTA4MjIwNzAwMDBaMBMCAgDU
Fw05OTA4MjQwNzAwMDBaMAkGByqGSM44BAMDLwAwLAIUfmVSdjP+NHMX0feW+aDU2G1cfT0C
FAJ6W7fVWxjBz4fvftok8yqDnDWhMYIB7DCCAegCAQEwGDASMRAwDgYDVQQDEwdDYXJsRFNT
AgIAyDAHBgUrDgMCGqBfMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHgYJKoZIhvcNAQkF
MREYDzIwMDAwNDI2MTkwMjAwWjAjBgkqhkiG9w0BCQQxFgQUQGrsCFJ5um4WAi2eBinAIpaH
3UgwCQYHKoZIzjgEAwQuMCwCFEgQuUNPhajwhZb7Qhy5Zc53RBHhAhRpI/JgWc4iFgU/JWRo
Po2y/X3MKKGCASIwggEeBgkqhkiG9w0BCQYxggEPMIIBCwIBATAmMBIxEDAOBgNVBAMTB0Nh
cmxSU0ECEEY0a8eAAFa8EdNuLsQQs7AwBwYFKw4DAhqgRTAeBgkqhkiG9w0BCQUxERgPMjAw
MDA0MjYxOTAyMDBaMCMGCSqGSIb3DQEJBDEWBBTsD+8vKk/UePnGe53FLE0wyGD9hDALBgkq
hkiG9w0BAQEEgYAwHAv0OVdDUgpMsGkKgMC0C5WbnCR7b2DPlkMoTUKs04zuwqv4lFnr+Jy2
BBU9tXkIl8DV+ARCUXN9KQPRzNy4vcRbkwtu3pzrhnC0OKS1RVD2MOtPlhcEL5dxWWSSomia
iRvbmVmQEE+qYjE/0LR3HE4p5OPNPmrqA0d4SakuUw==
--FL5UXtIhxfXey3p5
Content-Type: application/octet-stream
Content-Disposition: attachment; filename="5.10.bin"
Content-Transfer-Encoding: base64
MIIFFwYJKoZIhvcNAQcCoIIFCDCCBQQCAQExCTAHBgUrDgMCGjArBgkqhkiG9w0BBwGgHgQc
VGhpcyBpcyBzb21lIHNhbXBsZSBjb250ZW50LjGCBMUwggTBAgEBMBgwEjEQMA4GA1UEAxMH
Q2FybERTUwICAMgwBwYFKw4DAhqgggRcMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwIwYJ
KoZIhvcNAQkEMRYEFEBq7AhSebpuFgItngYpwCKWh91IMDgGAyqrMzExBC9UaGlzIGlzIGEg
dGVzdCBHZW5lcmFsIEFTTiBBdHRyaWJ1dGUsIG51bWJlciAxLjA6BgsqhkiG9w0BCRACBDEr
MCkMIENvbnRlbnQgSGludHMgRGVzY3JpcHRpb24gQnVmZmVyBgUqAwYFBDBKBgkqhkiG9w0B
CQ8xPTA7MAcGBSoDBAUGMDAGBioDBAUGTQQmU21pbWUgQ2FwYWJpbGl0aWVzIHBhcmFtZXRl
cnMgYnVmZmVyIDIwbQYLKoZIhvcNAQkQAgIxXjFcAgEBBgcqAwQFBgcIMTEwL4AIKgMEBQYH
hnihIxMhVEhJUyBJUyBBIFRFU1QgU0VDVVJJVFktQ0FURUdPUlkuExtUSElTIElTIEEgUFJJ
VkFDWSBNQVJLIFRFU1QwbwYLKoZIhvcNAQkQAgoxYDBeBgUqAwQFBgQrQ29udGVudCBSZWZl
cmVuY2UgQ29udGVudCBJZGVudGlmaWVyIEJ1ZmZlcgQoQ29udGVudCBSZWZlcmVuY2UgU2ln
bmF0dXJlIFZhbHVlIEJ1ZmZlcjBzBgsqhkiG9w0BCRACCzFkoGIwWjELMAkGA1UEBhMCVVMx
FjAUBgNVBAoTDVVTIEdvdmVybm1lbnQxETAPBgNVBAsTCFZEQSBTaXRlMQwwCgYDVQQLEwNW
REExEjAQBgNVBAMTCURhaXN5IFJTQQIEClVEMzCB/QYLKoZIhvcNAQkQAgMxge0wgeowgecE
BzU3MzgyOTkYEDE5OTkwMzExMTA0NDMzMFqhgckwgcakYTBfMQswCQYDVQQGEwJVUzEWMBQG
A1UEChMNVVMgR292ZXJubWVudDERMA8GA1UECxMIVkRBIFNpdGUxDDAKBgNVBAsTA1ZEQTEX
MBUGA1UEAxMOQnVncyBCdW5ueSBEU0GkYTBfMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNVVMg
R292ZXJubWVudDERMA8GA1UECxMIVkRBIFNpdGUxDDAKBgNVBAsTA1ZEQTEXMBUGA1UEAxMO
RWxtZXIgRnVkZCBEU0EwggECBgsqhkiG9w0BCRACCTGB8jCB7zFyAgEBBgcqAwQFBgcJMTww
OoAIKgMEBQYHhnihLhMsRVFVSVZBTEVOVCBUSElTIElTIEEgVEVTVCBTRUNVUklUWS1DQVRF
R09SWS4TJkVRVUlWQUxFTlQgVEhJUyBJUyBBIFBSSVZBQ1kgTUFSSyBURVNUMXkCAQEGByoD
BAUGBwoxPDA6gAgqAwQFBgeGeKEuEyxFUVVJVkFMRU5UIFRISVMgSVMgQSBURVNUIFNFQ1VS
SVRZLUNBVEVHT1JZLhMtRVFVSVZBTEVOVCBUSElTIElTIEEgU0VDT05EIFBSSVZBQ1kgTUFS
SyBURVNUMAkGByqGSM44BAMELjAsAhQE7dxQTjnC2qZ7Dh8qsoyFcmIPMwIUGHRabuAsU+tR
DyfkhZ3ll8nyeJQ=
--FL5UXtIhxfXey3p5--