All,
I agree with Denis' enhancement to Jim's Signing Certificate Attribute proposal.
Regarding Denis' last comment, CMS (sec 5.3 and 5.4) already requires two
separate hash calculations when authenticated attributes are used. First,
the content is hashed and the resulting hash value is included in the
messageDigest authenticated attribute. Then the DER-encoded
authenticatedAttributes are hashed. The signature value is generated from
the resulting hash value. In summary, CMS already specifies Denis'
recommendations.
================================
John Pawling
jsp(_at_)jgvandyke(_dot_)com
J.G. Van Dyke & Associates, Inc.
================================