David Shaw wrote:
On Sat, Nov 26, 2005 at 02:04:11PM +0000, Ben Laurie wrote:
I was working on my signing code and realised that some issues
previously discussed do not appear to be resolved in -15 (its possible
some of these are also new).
a) V4 signatures don't mention how one actually calculates the signature
- the text only appears for V3 signatures.
I'm not exactly sure what you mean here. Isn't this stated in 5.2.4,
in the paragraph beginning "Once the data body is hashed" ?
No, that tells you how to calculate the hash, not what you do with it
once you have calculated it. That is, padding, encryption, etc.
Cheers,
Ben.
--
http://www.apache-ssl.org/ben.html http://www.thebunker.net/
** ApacheCon - Dec 10-14th - San Diego - http://apachecon.com/ **
"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff