ietf-smime
[Top] [All Lists]

RE: Signing a SignedData object with RSA

1998-07-08 14:53:29
-----Original Message-----
From: EKR [mailto:ekr(_at_)terisa(_dot_)com]
Sent: Wednesday, July 08, 1998 7:39 AM
To: Russ Housley
Cc: abyskov(_at_)cryptomathic(_dot_)dk; ietf-smime
Subject: Re: Signing a SignedData object with RSA

Russ Housley <housley(_at_)spyrus(_dot_)com> writes:
- the signatureAlgorithm of the SignerInfo is to be a 
proper signature
algorithm, like sha1WithRSASignature

Correct.
Actually, no. At least not if we want to maintain compatibility
with PKCS-7. Remember that in PKCS-7, this field was known as
digestEncryptionAlgorithm. It's just rsaEncryption. 

This is correct.  This is what current S/MIME practice is, for exactly
the reason that Eric points out.

For further clarification, the OID is the one defined under PKCS #1
rsaEncryption, not the other five or six that you might find lying about
in other places.

I presume that this will all be covered when we start shoring up section
12 of CMS.

Blake
--
Blake C. Ramsdell
Worldtalk Corporation
For current info, check http://www.deming.com/users/blaker
Voice +1 425 882 8861 x103  Fax +1 425 882 8060

<Prev in Thread] Current Thread [Next in Thread>