I would guess, however rusty my crypto, that it's probably getting SHA-256 as the digest in the signature and it's getting a SHA-512 digested value. They're signing with alg A and signaling alg B basically (and of course, they shouldn't sign at all, problem solved). -- Scott