So, then use SHA-1 instead?  What do you mean by DSA being less common
than RSA?

Yes, use SHA-1. I exaggerate, but: nobody uses DSA in the real world. Why would they? It's 1K (or greater) RSA; cutting-edge folks use ECC.


Given the cryptographic naivete of your questions, you are better of using standard mechanisms like PKCS#7; see apps/pkcs7.c, e.g.

What advanteges does that offer me?

Less chance of you getting things wrong. Getting something wrong in the crypto field doesn't have to mean that your program will crash, it could mean that you make it easier than you expect for the bad guys to steal your information or defraud you or your clients.


Lastly, thanks for tolerating my newbieness, it's much appreciated. :)

Sure. Now that I look closer, apps/smime.c is really what you want to look it -- it shows how to call the PKCS7_xxx API.
/r$


--
Rich Salz, Chief Security Architect
DataPower Technology                           http://www.datapower.com
XS40 XML Security Gateway   http://www.datapower.com/products/xs40.html
XML Security Overview  http://www.datapower.com/xmldev/xmlsecurity.html

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to