-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Peter Walker wrote:
| But the peer uses RSA_PKCS1_PADDING. Is this interchangeable with OAEP?
No, it is not.

Without further information it is impossible to tell what these 16 bytes
are.

It could be some kind of ASN1 coding indicating that the following data
is a credit card information.
You need to ask the people doing the upstream server what
these 16 bytes are...

| -----Original Message-----
| From: [EMAIL PROTECTED]
| [mailto:[EMAIL PROTECTED] On Behalf Of Michael Sierchio
| Sent: 18 September 2008 10:02
| To: openssl-users@openssl.org
| Subject: Re: Do you have to pre-pend 16 bytes to a raw value before RSA
| encryption
|
| Peter Walker wrote:
|
|> The purpose of my application is to send a credit card number in
|> encrypted format.
|
| Then use OAEP.

For that the upstream server must also use OAEP.
Since it obviously doesn't, OAEP may theoretically be the better
solution but not usable in the situation at hand...


Goetz

- --
DMCA: The greed of the few outweighs the freedom of the many
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.4-svn0 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFI0oGZ2iGqZUF3qPYRAkR/AJ4np39sWs0Vgcs4Ljn7jD1hCHCqqQCbBD0p
1bwPYklaVQ94VnxqhixyQfA=
=VTKQ
-----END PGP SIGNATURE-----
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to