List Info

Thread: Multiple signatures over a document




Multiple signatures over a document
user name
2006-10-11 10:21:50
Hi!

I cannot resolve, how to correctly calculate multiple
signatures over
the document. I'm hashing entire document body + beginning
of
signature (as described in 2440), and everything is ok.
But, when I'm producing two old-style signatures :
1) GnuPG checks only the first one, and says that it's ok
2) PGP 8.1 checks both, but says that first one is invalid,
and the
second is ok

Producing two new-style signatures (with one-pass signature
packets),
getting :
1) GnuPG checks both, and says that they're correct.
2) PGP 8.1 checks both, and says that first is invalid, and
second one
is valid.

It seems, that PGP calculates the signature over the whole
document +
bodies of other signatures.

But from 2440 it seems, that signed hash must not include
other
signatures.

Please, anybody can clearly describe, what behavior is
correct?

And, maybe, such situation must be described in 2440?

--
  Best regards,Nickolay mailto:<ni4ukr.net>

Multiple signatures over a document
user name
2006-10-11 19:42:32
> I cannot resolve, how to correctly calculate multiple
signatures over
> the document. I'm hashing entire document body +
beginning of
> signature (as described in 2440), and everything is ok.
> But, when I'm producing two old-style signatures :
> 1) GnuPG checks only the first one, and says that it's
ok
> 2) PGP 8.1 checks both, but says that first one is
invalid, and the
> second is ok
>
> Producing two new-style signatures (with one-pass
signature packets),
> getting :
> 1) GnuPG checks both, and says that they're correct.
> 2) PGP 8.1 checks both, and says that first is invalid,
and second one
> is valid.
>
> It seems, that PGP calculates the signature over the
whole document +
> bodies of other signatures.
>
> But from 2440 it seems, that signed hash must not
include other
> signatures.
>
> Please, anybody can clearly describe, what behavior is
correct?
>
> And, maybe, such situation must be described in 2440?

Could you provide a sample document to show the issue?

	Jon

Multiple signatures over a document
user name
2006-10-12 15:53:21
Hello Jon,

JC> Could you provide a sample document to show the
issue?

I've sent it privately. Do you have any ideas 'bout?

--
  Best regards,Nickolay mailto:<ni4ukr.net>

Multiple signatures over a document
user name
2006-10-13 08:51:23
Hello Jon,

JC> Could you provide a sample document to show the
issue?
Hm, i've sent files as soon as you sent first request.
Maybe, there were some problems with mail server.
Here is second attempt :

1) two example keypairs (password for both is 'password').
2) encrypted and signed file without one-pass entities
3) encrypted and signed file with one-pass entities

-----BEGIN PGP PRIVATE KEY BLOCK-----
Version: PGP 8.1 - not licensed for commercial use:
www.pgp.com

lQHNBEOedR4RBAC6bfed3ULzOwVF/BouyO8kfs8wkOmk3vaMF6+6JyeEJqyI
maVh
pVhU7lst6QtXTyAF734FtClM/9Dq9Dn7GDoO3E9+nGVO7wJ1OT+X4lgkoiM6
8WWG
eioT958Hg0zq0KquHUBFM+Kldc+nr0e0Q6uCgwIYM7oH60/WX8e2WnvycwCg
zba0
kRzxNtmw9w9IEQUk9pa2CK8D/2FjRxtEDN6nY7/l1wUrkMjI/uXYnsNWwrIA
bwHp
qhUZQYst27XpwNplAmI6YuS+3O+L4vgURj1hVcnNG+2bZXjbt4Fg3RLhrTV/
jiuL
ohBayAAdZZ4+72Cja1+18xp700GVTF96jYc8dIoxNx1AgHzQUffj3GnscAzo
7ud3
HyYHA/9sI6Gijh/ubr1qTzHwZPdilDjfnEyQwR6+forUUegwCO0YawsC2lG6
F7MG
q3RHnJSwI3DiH/gY5bYk3XxhinkKxqk54DiL6vrHIw/E9J6RazY+ocicLRZ+
6XjO
JPXpK8s2v64pH5gyrsfANwSTTyECPx/hp2G+0BW/mtMU+JqFPP8DAwKvgRN0
8aTW
1WAW5/ak/URD4OAOT6OXlyg4YwhaJodb9vfwck4V8bnNLVNhbXBsZSBTZWN1
cmVC
bGFja2JveCBQR1Aga2V5PGluZm9AZWxkb3MuY29tPp0DJgRDnnWkEAgAxIwI
smEC
mLGfQMH6GfNqn8XG9/bvT/nL/m7TjUVv1JGrKDASbASsPlYLnDel4opyp24A
zu5x
nQ0/QlsOifmXjINcWzNtWcJkW3rBamP1Vw6ZhxN8e1ARRrxwOn42V/yn/HoM
FH0O
Hhm2M5r8W/rOxo4dPdKPmRPdMaPVMndgM8WcOGPJ6TbMb4g9hphb+E4o3glI
6fhP
41GZy57wWdKY9DnQ3W2PGoFaFAlQdyAtekzOmixp2/jXpq4+br9Yd088Unp2
sw4Z
56j8sAbTk7NFpcTUSxsnFXpiGr0WkV+qfDyYTBvEnFXIteiThAWYzJgge6Tb
6qzL
1XjD5uR1z2FgTwACAgf/fGBkVe8yETYwARrcn0xXv991AEvA4wlNI0/gygJK
XxTV
0wTImdsOnsKsxtTCKdchSCFRuGYsBPzc7lUsPKk4jNkAv1EZELhqHkZTC51t
EPxA
m3/i8iAYFz2rTPfZkrjBJ2xP6ChRqmj0BTcZjo3bzRwjlUMTejGaR9BQDqB9
A59z
2rCBn6nz9f6F+1oZ62gThjS6WUbUbhBKCwvfntFsXFrpXWHr5Apv+5zbxteT
dHr0
1x3NRl0RzvzJ4wQ4WsVFiZFI3l7HykRd37XE+hSvRSr2iWqE/PdR7alxAswc
5LET
GCH//3xzP1/7Au3XLUaD4LaFoXY1bIBui2Srmu1kcP8DAwIYqvVK6L5Df2Ce
jmTt
hiA1DBnNck4dF7gPOaYku6Rfw27EOvhWmdZ1pp13uw2Tm6SEBoG7rkq1a01U
WEjs
PhUPkfxhVT6qHd4Bs3EOGSh7sNFsv8IbbAyP3rPOtbt3m9t02xEzKl5ZOqD8
5EZC
HYK/l6lLD8pUX2dJQqZwTN4lkdl99HOf7XYPxHvCmbh1S1CgTM3H2wc5M7QR
OMhr
jxPIu0kJUONw1PX5TuLGU6BOjii0VLzljLHgi7uuTRxE7P4GqPV3Fmv+GANS
GFiN
4751R1IBLnL0EMfOrFkHikCx+QvIDiHvsH+inSuguqHvtN6CA2WZLKN3mWtQ
mq1K
9tuuXf7Ko6LJb2yetoEpCL31RRaxeRMX
=oQP9
-----END PGP PRIVATE KEY BLOCK-----
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: PGP 8.1 - not licensed for commercial use:
www.pgp.com

mQGiBEOedR4RBAC6bfed3ULzOwVF/BouyO8kfs8wkOmk3vaMF6+6JyeEJqyI
maVh
pVhU7lst6QtXTyAF734FtClM/9Dq9Dn7GDoO3E9+nGVO7wJ1OT+X4lgkoiM6
8WWG
eioT958Hg0zq0KquHUBFM+Kldc+nr0e0Q6uCgwIYM7oH60/WX8e2WnvycwCg
zba0
kRzxNtmw9w9IEQUk9pa2CK8D/2FjRxtEDN6nY7/l1wUrkMjI/uXYnsNWwrIA
bwHp
qhUZQYst27XpwNplAmI6YuS+3O+L4vgURj1hVcnNG+2bZXjbt4Fg3RLhrTV/
jiuL
ohBayAAdZZ4+72Cja1+18xp700GVTF96jYc8dIoxNx1AgHzQUffj3GnscAzo
7ud3
HyYHA/9sI6Gijh/ubr1qTzHwZPdilDjfnEyQwR6+forUUegwCO0YawsC2lG6
F7MG
q3RHnJSwI3DiH/gY5bYk3XxhinkKxqk54DiL6vrHIw/E9J6RazY+ocicLRZ+
6XjO
JPXpK8s2v64pH5gyrsfANwSTTyECPx/hp2G+0BW/mtMU+JqFPM0tU2FtcGxl
IFNl
Y3VyZUJsYWNrYm94IFBHUCBrZXk8aW5mb0BlbGRvcy5jb20+wkkEEBECABMC
mQEF
AkOedaQJEKl84ZsqNet0AAAROgCggFcJOrmvNvpdmADv0iEzVUVci+gAoJDD
9wbm
WOq7M06k4rSOZSj2me0GuQINBEOedaQQCADEjAiyYQKYsZ9AwfoZ82qfxcb3
9u9P
+cv+btONRW/UkasoMBJsBKw+VgucN6XiinKnbgDO7nGdDT9CWw6J+ZeMg1xb
M21Z
wmRbesFqY/VXDpmHE3x7UBFGvHA6fjZX/Kf8egwUfQ4eGbYzmvxb+s7Gjh09
0o+Z
E90xo9Uyd2AzxZw4Y8npNsxviD2GmFv4TijeCUjp+E/jUZnLnvBZ0pj0OdDd
bY8a
gVoUCVB3IC16TM6aLGnb+Nemrj5uv1h3TzxSenazDhnnqPywBtOTs0WlxNRL
GycV
emIavRaRX6p8PJhMG8ScVci16JOEBZjMmCB7pNvqrMvVeMPm5HXPYWBPAAIC
B/98
YGRV7zIRNjABGtyfTFe/33UAS8DjCU0jT+DKAkpfFNXTBMiZ2w6ewqzG1MIp
1yFI
IVG4ZiwE/NzuVSw8qTiM2QC/URkQuGoeRlMLnW0Q/ECbf+LyIBgXPatM99mS
uMEn
bE/oKFGqaPQFNxmOjdvNHCOVQxN6MZpH0FAOoH0Dn3PasIGfqfP1/oX7Whnr
aBOG
NLpZRtRuEEoLC9+e0WxcWuldYevkCm/7nNvG15N0evTXHc1GXRHO/MnjBDha
xUWJ
kUjeXsfKRF3ftcT6FK9FKvaJaoT891HtqXECzBzksRMYIf//fHM/X/sC7dct
RoPg
toWhdjVsgG6LZKua7WRwwkYEGBECABAFAkOedaQJEKl84ZsqNet0AAClZQCe
O/j6
lgFT70PtDgN4yQVf4pDQSgkAnRbRTzcQjdddx7f74i4WgCcUf2XE
=nyli
-----END PGP PUBLIC KEY BLOCK-----

-----BEGIN PGP PRIVATE KEY BLOCK-----
Version: PGP 8.1 - not licensed for commercial use:
www.pgp.com

lQOsBEOedkIBCAD2dr9Dj2Y1o15FAfkrWtz5lHF88Ceza1sMDu7BwsGZdpxY
F2hS
2OhYr6l5z58t6CccFVWz+Ao9sZJUAka0KjhfqQnAWmzqk8kh0dzn7KcooBx0
AUWK
6OKUY9HEUuJSfuN3I059m/EiIPXbdSjwLabEqirZStyDPodkB5kaqy0iAyRl
2Uw6
r9VUZ837iaXR524Oql9VKangtssFAmZqIxDgcJSfiitprVmTzzg94J6alPWr
Jevs
syDvUyjKqVQrfHEbh5+r1xewsFW4E/2aHn8W1Q+rEsMC89lTOxg49kT5RSgu
Zj6F
dGfISvh2OHHz4Elbdwa5YFDp3Xc7Btia2WmNABEBAAH/AwMC8k0YTRdu5iBg
EEov
y8JOxHkWDBltYnc0ZUsRczBLl43OWohORXOxcR6YZUvvsdEtCxmL+RDNxj3t
IpmO
f7S5TM/nGxksi6ULDgywaU+e4hhtZwGtS7GFupLUYbhwV0DkgRaMH2BVJ8vY
TRZy
qKhPAv0saAnnfUkmAtuQUKk0VYCZpNjrl4gC0Gg0tCcT9q+41WDt498HYjoc
YNy8
hCu0FmUoiGkM3VXTLCP6KxOHBHb63EaljSqR7lXCIFtFmYfmyR3JfdbUElE5
sWyX
q4JMO8fakiNsCNTrwMgvHLJaZs+VG+0Ifc3FoMkigsahWHI3iOzA82Wu+ZiX
x20y
IH0kKKdYruoF92dUZtJM3y+rCEdmKYDTQpzjOQ10wp0vN4hvALUTzsceGM8Y
pH/B
5xvOoWMWy1XyuU55XJtMH2GyinJGVjfiPbqfw2I/82W8sJBkEmv3mOMe12Qy
jzV/
hO/BhddTVG0zKVVu01xLuW/myTJWaBa1rcCbGmYo2xKhIY4eymFkAA2QEBmO
hlXM
x2Xpfkq0v7ipZax1yW9OI8bz0Qn4xxg3yhIw6m7aAMkEC0sFvYxuCoG83eL5
E+bo
+EPJ1P9naIjnTozdvRknWEYiQYb6a7wyZ3wofe61RN9Up29QypsCPTiIl0Vp
CX/I
MptCF7yA5LoG9vNfWAVAn1F9tv3GYUzsYR4MW8NkFNpRfbngTtnyn1u61l8i
j9fw
XCLlClSVj35naqAJ3NGD8WNcs1Vi4rkcMDWga3ch5kDXyhIJC6d9XRFxpDK/
Q0Iq
LeLFPqTwiIsmWy2SUXfLBn4utEzn1ZMWjPSuzYDSlZuSo1SvHZBBF4N538HT
x1QP
+gLUkmll3LO9E7Wmd4PTR4ds2BWDgfUOx1atwSlfzs0tU2FtcGxlIFNlY3Vy
ZUJs
YWNrYm94IFBHUCBrZXk8aW5mb0BlbGRvcy5jb20+
=+GSA
-----END PGP PRIVATE KEY BLOCK-----
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: PGP 8.1 - not licensed for commercial use:
www.pgp.com

mQENBEOedkIBCAD2dr9Dj2Y1o15FAfkrWtz5lHF88Ceza1sMDu7BwsGZdpxY
F2hS
2OhYr6l5z58t6CccFVWz+Ao9sZJUAka0KjhfqQnAWmzqk8kh0dzn7KcooBx0
AUWK
6OKUY9HEUuJSfuN3I059m/EiIPXbdSjwLabEqirZStyDPodkB5kaqy0iAyRl
2Uw6
r9VUZ837iaXR524Oql9VKangtssFAmZqIxDgcJSfiitprVmTzzg94J6alPWr
Jevs
syDvUyjKqVQrfHEbh5+r1xewsFW4E/2aHn8W1Q+rEsMC89lTOxg49kT5RSgu
Zj6F
dGfISvh2OHHz4Elbdwa5YFDp3Xc7Btia2WmNABEBAAHNLVNhbXBsZSBTZWN1
cmVC
bGFja2JveCBQR1Aga2V5PGluZm9AZWxkb3MuY29tPsLAXwQQAQIAEwKZAQUC
Q552
QgkQYQ5in2dng7UAADHTB/9cPWXdNlG5ZB9ysXQSEEBrO42ZFeNDRW1yIELd
MXdi
uyecOuxFO0WKictGspLysGULQI6XZmxmM3C7zIFW6KoeNDNIQB/aBj/BbFsa
vr7Y
P0yRN+2g4lgviDJrlbRnVRuW6BjguP6BOPiKsunGPX0kQ0BqKvxBdICJJ4+W
SdNL
Yo/sPgAy3FY35xAD0//MRWmFodgQ7xT402NmzppXptB5u/2jf/gPpLOmD8xg
CS1q
EiKuFNFMEO9nMDbcBHMH9VmqKt0XnZaEomOAVuGGpRn27LO7tcoZiFmMJpIe
fNLU
zS94tzNWUMKKb1QnMJ7zJf1Wz5SpADDqZAX5dK1xvEKK
=i+vp
-----END PGP PUBLIC KEY BLOCK-----

-----BEGIN PGP MESSAGE-----
Version: EldoS PGPBlackbox

wcBMA2EOYp9nZ4O1AQf/U090w5aCiUItJwjEDG7Xlzj65ZNpkPkH8ASfG4BC
qIFN
OOQ7y2DivVgJgYOxVy1tivoJu3pecxw8sBHNi40TtfO3LKfQEmzUpDS+BWJt
fFYz
IfOfzh+dS1ykYvDpg9KquXBLFTCQooD0d5gbJwrH4vAwXsd0srR80lz1DOGo
ypn6
/xV0TvwFisiXgrb2bHWCEG/Ds/qFpvq+hreJeMUSHICAEfOOxImxWFfKySPp
92Yr
+Ou6dJdXiMmFy9X9jlZ4A271Q/MtTcYzYg4bshiRDfMBitcMdzVBRsB7DMqo
UKOV
3eUenFa3mIdLhbYrIGhU9GjGsdBlC2ntm1iJAQVZ0MnA0cxqub+Vj/tqy4Ks
bxwK
LM99r63MYB/l2GtklCd9r5WTOe6f9mOlQOcuUsQgOh9LSiv3gw7Xu2X2Fasu
/O9e
xswyYrUIp8uYS9GPtOC+olmh0A6FjkNexX/GNDMy8ES8/CwK7WQcB0bFDfMu
OwLK
EwMVCmIA9CovNccYCUfFZqTNP9mDNlEDCeppscBs+Q3OY4DfFjS5SAcdYdS/
bfuQ
DCGlxji/3weqyIBHblEmPxwYjKKC5+O4pf93ACulw3GI+VWAHA8FsLKgL2Ld
wKYG
YR60JYEe55J4j1Wu1QL9KHzgfw+UVm7I7Q8jLA7ZTCr4kjHYUbhz1kfRLZZB
LuEX
5J9PMRWigxPJ37HWtnPtIS9vhV5Vi4VOJjX0GPWebmpmfHTykhhMyk6JavXN
+MEW
1CboilXFEcwlpQFL254VWbEgNu3uCWv48qE2U3oRG+sp1mB2+wXX6Wb/nCnO
Rq6P
8rzWWw010ShRcE17h18DIp3idgG6ufpbZ0AP6XjylvsvLUP4AkT0Hx8vhehc
c8aR
HTLQ
=gsjO
-----END PGP MESSAGE-----

-----BEGIN PGP MESSAGE-----
Version: EldoS PGPBlackbox

wcBMA2EOYp9nZ4O1AQgA0xOIGF4JtHPQtlK0sCQsCwHtq1z1EG3Wef7VsAln
4WjQ
OhNp8F/+FtyRbfAlvOZNlBRyTXvc84Y4/OsQ8c/ColxSU4JxPlsjQ4FwhQrW
wYE1
4BeGbB3LRq90/p94Ji0XMlMCxfz90yKHPAa2QDfEM2Zv1niwSPm8Nu7DdZpX
9lab
TYs3NbWsdmpHzhif5enVcAVEXSPpFdwFzne1Qng4lnyiPk4Cvq19R1oyu4p6
WF/j
bww3JigYIscHgXxKb1V+VYdNihojXnInA4m5HfIcLAX3WX1G6Gw9eyb/Ygk/
IjMv
WIcUks1IK/dfZXmd5YGJ3xhl5tHYlW9seuw4b+2krtLBBgGQSS3E077cD0si
sTdU
MhEe/0Xx6yo5GQuEjrQC/P60DtsJ4kGJJWSGSJddIX+jQcNaxRVWTGd48Ewg
Fni6
IPaxvgyL/BJgHrGMHy59vMue8VeSxVCnrkj4FJBqKn3/D7j4JzDOdRXy6c/7
vsaC
YpPj/UL4GtZW+xm8k4KRIkZbuiM9O8AvsZEp6Fsfpju4FAY+GFDec8hosdq9
tcjg
tSfjqUg/AvrrS8A6kWnUsw9zynF5++Kp5pXPVVC3Qs+S9zMzS1pKVGg9VgA0
efuf
byLomDAIkBXnBf6DagWwTSfw6eKV8YsswLEnXVearu1qX+HAliRmr+qBGe7r
zPz3
zVZbaC2BxDukT0Nt9Ofj1WI3iM3NytNuzMJv8Owvjeamady5ynfYkfTTBaSP
A3/A
q7vfDemPOrCDJnLTePrJokqhJDMoIAjYgXDrvkTfwfgQAvvJGd8eHiPRNfBf
nzR1
K/ouKgr6I4Flj5STfvSePs52iL31tMujIhIPBNKhzsyPlAXk4mbPphOoeoT5
sQtN
r3HQTA//+qn9X7zZHLVj7weefRu0igcq6PZ/FBTWTly2hg4Quld6lltl2saY
+yIb
Q8dOU55WqJ0=
=7bNN
-----END PGP MESSAGE-----


--
  Best regards,Nickolay mailto:<ni4ukr.net>


[1-4]

about | contact  Other archives ( Real Estate discussion Medical topics )