AW: XMLDSIG RSA signatures

Hi Joseph,

> And we control what [1] means, consequently does anyone oppose Merlin's
> first option [2]?

Yes, I strongly oppose Merlin's first option:

* We cite RSASSA-PKCS1-v1_5 as normative reference, and encrypting the
  raw digest instead of the ASN.1 structure is not an option there.

* As Phil stated in [1], the OID for the digest algorithm has been added
  to prevent a chosen digest attack.

* To allow this option only because WTLS does it, is not a really good


Regards, Gregor
Gregor Karlinger
Phone +43 316 873 5541
Institute for Applied Information Processing and Communications

Received on Wednesday, 30 August 2000 02:38:23 UTC