On Wed, Mar 17, 2004, [EMAIL PROTECTED] wrote:

> from Pk7_doit.c
> 
>    if ((sk != NULL) && (sk_X509_ATTRIBUTE_num(sk) != 0))
>     {
>     unsigned char md_data[EVP_MAX_MD_SIZE], *abuf=NULL;
>     unsigned int md_len, alen;
>     ASN1_OCTET_STRING *digest;
>     ASN1_UTCTIME *sign_time;
>     const EVP_MD *md_tmp;
> 
>     /* Add signing time if not already present */
>     if (!PKCS7_get_signed_attribute(si,
>        NID_pkcs9_signingTime))
>      {
>      sign_time=X509_gmtime_adj(NULL,0);
>      PKCS7_add_signed_attribute(si,
>       NID_pkcs9_signingTime,
>       V_ASN1_UTCTIME,sign_time);
>      }
> 
>     /* Add digest */
>     md_tmp=EVP_MD_CTX_md(&ctx_tmp);
>     EVP_DigestFinal_ex(&ctx_tmp,md_data,&md_len);
>     digest=M_ASN1_OCTET_STRING_new();
>     M_ASN1_OCTET_STRING_set(digest,md_data,md_len);
>     PKCS7_add_signed_attribute(si,
>      NID_pkcs9_messageDigest,
>      V_ASN1_OCTET_STRING,digest);
> 
>     /* Now sign the attributes */
>     EVP_SignInit_ex(&ctx_tmp,md_tmp,NULL);
> 
> 
>     Seems that EVP_DigestFinal_ex and then EVP_SignInit_ex reinitialize MD
> calculation.
>     Then
> 
>     alen = ASN1_item_i2d((ASN1_VALUE *)sk,&abuf,
>        ASN1_ITEM_rptr(PKCS7_ATTR_SIGN));
>     if(!abuf) goto err;
>     EVP_SignUpdate(&ctx_tmp,abuf,alen);
> 
>     calculate digest only on attributes.
> 
>     Where is my error?
> 

If attributes are present the mesageDigest attribute contains the digest of
the message content. The encoding of the attributes is then signed. That was
always the intention (and what the various interop tests used) but the wording
sometimes didn't make it clear.

See for example RFC3369 5.4:

"When the field [signedAttrs] is present, however, the result is the message
digest of the complete DER encoding of the SignedAttrs value
contained in the signedAttrs field.  Since the SignedAttrs value,
when present, must contain the content-type and the message-digest
attributes, those values are indirectly included in the result."

Steve.
--
Dr Stephen N. Henson. Email, S/MIME and PGP keys: see homepage
OpenSSL project core developer and freelance consultant.
Funding needed! Details on homepage.
Homepage: http://www.drh-consultancy.demon.co.uk
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to