Hi,

Is this error related to the usage of MD2/MD5 as a hash function for RSA
signature algorithm, which is outdated? If not, what is the reason why this
error is raised? I'm sorry if I'm asking now but when I asked I was just
interested in the error itself, not in the issue which causes it. But now I
need to know it.

Thank You Very Much,

Nicholas

2016-03-30 21:59 GMT+02:00 David Keeler <dkee...@mozilla.com>:

> -8016 is SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED (see
>
> https://dxr.mozilla.org/mozilla-central/rev/d5d53a3b4e50b94cdf85d20690526e5a00d5b63e/security/nss/lib/util/secerr.h#207
> ).
>
> Cheers,
> David
>
> On 03/30/2016 12:49 PM, Nicholas Mainardi wrote:
> > Hello,
> >
> > I am parsing and validating a sample of certificate chains. I am using
> > PKIXVerifyCert function, and i check the error code in case it returns
> > SECFailure. On a chain which is made by only one certificate, I got error
> > -8016. However, I don't find it neither in this list
> > <
> http://www-archive.mozilla.org/projects/security/pki/nss/ref/ssl/sslerr.html
> >
> > nor
> > in NSPR defined error (ones starting from -6000). What kind of error is
> > this?
> >
> > If you need the certificate, it is ASN1 parsed here
> > <
> https://lapo.it/asn1js/#3082067D30820565A00302010202020103300D06092A864886F70D01010405003081AF310B30090603550406130248553110300E0603550408130748756E676172793111300F06035504071308427564617065737431273025060355040A131E4E65744C6F636B2048616C6F7A617462697A746F6E73616769204B66742E311A3018060355040B131154616E7573697476616E796B6961646F6B313630340603550403132D4E65744C6F636B204B6F7A6A6567797A6F692028436C6173732041292054616E7573697476616E796B6961646F301E170D3939303232343233313434375A170D3139303231393233313434375A3081AF310B30090603550406130248553110300E0603550408130748756E676172793111300F06035504071308427564617065737431273025060355040A131E4E65744C6F636B2048616C6F7A617462697A746F6E73616769204B66742E311A3018060355040B131154616E7573697476616E796B6961646F6B313630340603550403132D4E65744C6F636B204B6F7A6A6567797A6F692028436C6173732041292054616E7573697476616E796B6961646F30820122300D06092A864886F70D01010105000382010F003082010A0282010100BC748C0FBB4CF4371EA90582D8E6E16C70EA78B56ED138440DA883CE5D
 D
> >
> 2D6D581C5D44BE75B947026DB3B9D6A4C62F771F364D6613B3DEB73A337D9CFEA8C923BCDF707DC667497F44522DDF45CE0BF6DF3BE6533E4153ABFDB98905538C4EDA655630BB07804F4E36EC13F8EFC51781F929E83C2FED9B0A9C9BC5A00FFA9A89874FBF62C3E15390DB60455A80E982042B3B125AD7E9A6F5D53B1AB0CFCEBE0F37AB3A8B3FF46F663A2D83A987BB6AC85FFB0254F7463E71307A50A8F05F7C0646F7EA7278096DED42E8660C76B2B5E737B17E7913F640CD84B22342B9B32F2481F9FA10A847AE2C2AD973D8ED5C1F956A350E9C6B4FA98A2EE95E62A038CDF0203010001A382029F3082029B300E0603551D0F0101FF04040302000630120603551D130101FF040830060101FF020104301106096086480186F84201010404030200073082026006096086480186F842010D048202511682024D46494759454C454D2120457A656E2074616E7573697476616E792061204E65744C6F636B204B66742E20416C74616C616E6F7320537A6F6C67616C7461746173692046656C746574656C656962656E206C6569727420656C6A617261736F6B20616C61706A616E206B65737A756C742E204120686974656C65736974657320666F6C79616D617461742061204E65744C6F636B204B66742E207465726D656B66656C656C6F737365672D62697A746F736
 9
> >
> 7461736120766564692E2041206469676974616C697320616C616972617320656C666F6761646173616E616B2066656C746574656C6520617A20656C6F69727420656C6C656E6F727A65736920656C6A61726173206D6567746574656C652E20417A20656C6A61726173206C656972617361206D656774616C616C6861746F2061204E65744C6F636B204B66742E20496E7465726E657420686F6E6C61706A616E20612068747470733A2F2F7777772E6E65746C6F636B2E6E65742F646F63732063696D656E2076616779206B65726865746F20617A20656C6C656E6F727A6573406E65746C6F636B2E6E657420652D6D61696C2063696D656E2E20494D504F5254414E5421205468652069737375616E636520616E642074686520757365206F662074686973206365727469666963617465206973207375626A65637420746F20746865204E65744C6F636B2043505320617661696C61626C652061742068747470733A2F2F7777772E6E65746C6F636B2E6E65742F646F6373206F7220627920652D6D61696C20617420637073406E65746C6F636B2E6E65742E300D06092A864886F70D01010405000382010100482446F7BA566FFAC82803404EE531396B266B537FDBDFDFF3713D26C0140EC6677B23A80C73DD01BBC6CA6E373955D5C78C56200E280A0ED22AA4B04952
 C
> >
> 63807FEBE0A098CD198CFCADA1431A14FD239FC0F112C43C3DDAB93C7553E477C181A00DCF37BD8F27F526C20F40B5F6952F4EEF8B22960EBE34931210DD6B51041E241096CE21A9A564B7702F6A09B9A2787E8552971C2909F45781AE115643DD00ED8A0769FAEC5D02EEAD60F56EC647F5A9B145801277E1350C76B2AE6683CBF5CA00A1BE10E7AE9E280C3E9E9F6FD6C119ED0E528272B543242148275E64AF02B6675638CA2FB043E830E9B36F018E42620C38CF02807AD3C176688B5FDB688>,
> > and you find the PEM version in the box below.
> >
> > Thank You very much,
> >
> > Nicholas
> >
>
>
> --
> dev-tech-crypto mailing list
> dev-tech-crypto@lists.mozilla.org
> https://lists.mozilla.org/listinfo/dev-tech-crypto
>
-- 
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to