Why requiring --certificate when verifySignature?
Ian Young
ian at iay.org.uk
Thu Oct 8 16:48:27 UTC 2020
> On 2020-10-08, at 17:45, Ian Young <ian at iay.org.uk> wrote:
>
> you might argue that this would give you integrity protection
By which I mean to imply _passive_ integrity protection. It's no good for that either in the face of an attacker who can strip the signature and replace it with one of their own.
-- Ian
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20201008/5b0601d5/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3883 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/dev/attachments/20201008/5b0601d5/attachment.p7s>
More information about the dev
mailing list