Re: comments and corrections for draft-ietf-smime-examples-06

[email protected] Fri, 23 Mar 2001 15:25:02 -0500
Newsgroups gmane.ietf.smime-examples
Message-ID <[email protected]>


Hello guys. I've unsubscribed some time ago, but recently started to get the
e-mails again. Can someone please remind how to unsubscribe? Thanks.





Dr S N Henson <[email protected]> on 23.03.2001 15:00:29

Sent by:  Dr S N Henson <[email protected]>


To:   [email protected]
cc:    (Victor Baranov/C/CA/3Com)
Subject:  Re: comments and corrections for draft-ietf-smime-examples-06



Hmmm... I hadn't noticed someone had already reported problems with
example 5.1 when I posted the query...


"Life is hard, and then you die" wrote:
>
>
> 4) Examples 5.1, 5.3, 5.6, 5.7, SignedData:
>         I'm unable to verify the signatures on these. To double check,
>         I've extracted the raw signature bytes and the public key and
>         took the ExContent.bin, and they still won't verify, so I'm
>         assuming the examples are at fault.
>
>         Also, a hint that the examples might be screwed is that the
>         signatures contain a spurious 0 byte at the end (in the case of
>         5.3 there are actually two of them): if you do the math on the
>         last octet string in the SignerInfo, you'll see that while it
>         always has length 48, the dsa signature within is actually only
>         47 bytes long (46 bytes in the case of 5.3).
>
...

>
> 6) Examples 5.8 and 5.9, signed mails:
>         These have both the above problems, i.e. wrong OId, spurious
>         0 byte at the end, and signature won't verify.
>
> Interestingly, I can't verify any DSA signatures created by Jim Schaad;
> those created by John Pawling I can (after fixing the OId).
>

I've done some further tests using OpenSSL and I agree with this DSA
signature problem: I can verify the [JP] DSA examples but not the [JS]
ones.

Steve.
--
Dr Stephen N. Henson.   http://www.drh-consultancy.demon.co.uk/
Personal Email: [email protected]
Senior crypto engineer, Celo Communications: http://www.celocom.com/
Core developer of the   OpenSSL project: http://www.openssl.org/
Business Email: [email protected] PGP key: via homepage.