RE: comments and corrections for draft-ietf-smime-examples-06
"Pawling, John" <[email protected]> Fri, 23 Mar 2001 15:25:56 -0500
| Newsgroups | gmane.ietf.smime-examples |
|---|---|
| Message-ID | <[email protected]> |
Steve, We will re-test all of these messages using the S/MIME Freeware Library. =========================================== John Pawling, [email protected] Getronics Government Solutions, LLC =========================================== -----Original Message----- From: Dr S N Henson [mailto:[email protected]] Sent: Friday, March 23, 2001 3:00 PM To: [email protected] Subject: Re: comments and corrections for draft-ietf-smime-examples-06 Hmmm... I hadn't noticed someone had already reported problems with example 5.1 when I posted the query... "Life is hard, and then you die" wrote: > > > 4) Examples 5.1, 5.3, 5.6, 5.7, SignedData: > I'm unable to verify the signatures on these. To double check, > I've extracted the raw signature bytes and the public key and > took the ExContent.bin, and they still won't verify, so I'm > assuming the examples are at fault. > > Also, a hint that the examples might be screwed is that the > signatures contain a spurious 0 byte at the end (in the case of > 5.3 there are actually two of them): if you do the math on the > last octet string in the SignerInfo, you'll see that while it > always has length 48, the dsa signature within is actually only > 47 bytes long (46 bytes in the case of 5.3). > ... > > 6) Examples 5.8 and 5.9, signed mails: > These have both the above problems, i.e. wrong OId, spurious > 0 byte at the end, and signature won't verify. > > Interestingly, I can't verify any DSA signatures created by Jim Schaad; > those created by John Pawling I can (after fixing the OId). > I've done some further tests using OpenSSL and I agree with this DSA signature problem: I can verify the [JP] DSA examples but not the [JS] ones. Steve. -- Dr Stephen N. Henson. http://www.drh-consultancy.demon.co.uk/ Personal Email: [email protected] Senior crypto engineer, Celo Communications: http://www.celocom.com/ Core developer of the OpenSSL project: http://www.openssl.org/ Business Email: [email protected] PGP key: via homepage.