"Bad signature length" in request

Cantor, Scott cantor.2 at osu.edu
Wed Aug 13 16:52:10 UTC 2025


I would guess, however rusty my crypto, that it's probably getting SHA-256 as the digest in the signature and it's getting a SHA-512 digested value. They're signing with alg A and signaling alg B basically (and of course, they shouldn't sign at all, problem solved).

-- Scott





More information about the users mailing list