Why requiring --certificate when verifySignature?

Ian Young ian at iay.org.uk
Thu Oct 8 16:48:27 UTC 2020


> On 2020-10-08, at 17:45, Ian Young <ian at iay.org.uk> wrote:
> 
> you might argue that this would give you integrity protection


By which I mean to imply _passive_ integrity protection. It's no good for that either in the face of an attacker who can strip the signature and replace it with one of their own.

    -- Ian




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20201008/5b0601d5/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3883 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/dev/attachments/20201008/5b0601d5/attachment.p7s>


More information about the dev mailing list