So, then use SHA-1 instead? What do you mean by DSA being less common than RSA?
Yes, use SHA-1. I exaggerate, but: nobody uses DSA in the real world. Why would they? It's 1K (or greater) RSA; cutting-edge folks use ECC.
Given the cryptographic naivete of your questions, you are better of using standard mechanisms like PKCS#7; see apps/pkcs7.c, e.g.
What advanteges does that offer me?
Less chance of you getting things wrong. Getting something wrong in the crypto field doesn't have to mean that your program will crash, it could mean that you make it easier than you expect for the bad guys to steal your information or defraud you or your clients.
Lastly, thanks for tolerating my newbieness, it's much appreciated. :)
Sure. Now that I look closer, apps/smime.c is really what you want to look it -- it shows how to call the PKCS7_xxx API.
/r$
-- Rich Salz, Chief Security Architect DataPower Technology http://www.datapower.com XS40 XML Security Gateway http://www.datapower.com/products/xs40.html XML Security Overview http://www.datapower.com/xmldev/xmlsecurity.html
______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]
