Re: [openssl-users] Verify signature without certificate included in it

2016-04-23 Thread c.hol...@ades.at

Ahh... i see.
-certfile

Thanks!

Chris


On 2016-04-22 20:22, c.hol...@ades.at wrote:

hi!

I am using openssl-smime for signing outgoing messages and verifying 
incoming.

My question is about verifying.

If the partner signs a message where the certificate is included in 
the signature all is OK.
If he signes only with issuer and serial included in the signature i 
get an error ("signer certificate not found").


If I parse the signature with openssl-asn1parse I can see the content 
of the signature. So I see whats included.


Do not know how to describe it in a better way. Is there a name for 
signatures with/without certificate-information?


How can I get the signature get verifyed if there is no certificate 
included in it?


Thanks for help!
Chris



--
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users


Re: [openssl-users] Verify signature without certificate included in it

2016-04-22 Thread Dr. Stephen Henson
On Fri, Apr 22, 2016, c.hol...@ades.at wrote:

> hi!
> 
> I am using openssl-smime for signing outgoing messages and verifying
> incoming.
> My question is about verifying.
> 
> If the partner signs a message where the certificate is included in
> the signature all is OK.
> If he signes only with issuer and serial included in the signature i
> get an error ("signer certificate not found").
> 
> If I parse the signature with openssl-asn1parse I can see the
> content of the signature. So I see whats included.
> 
> Do not know how to describe it in a better way. Is there a name for
> signatures with/without certificate-information?
> 
> How can I get the signature get verifyed if there is no certificate
> included in it?
> 

The certificate contains the public key used to verify the signature.
If the certificate isn't included in the message itself it can be supplied
separately either with the API or the command line.

Steve.
--
Dr Stephen N. Henson. OpenSSL project core developer.
Commercial tech support now available see: http://www.openssl.org
-- 
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users