[openssl-dev] [openssl-users] PKCS7_sign conflict with PKCS7_decrypt?

Blumenthal, Uri - 0553 - MITLL uri at ll.mit.edu
Thu Aug 4 20:30:15 UTC 2016


On 7/26/16, 15:24 , "openssl-users on behalf of Dr. Stephen Henson"
<openssl-users-bounces at openssl.org on behalf of steve at openssl.org> wrote:

>On Tue, Jul 26, 2016, Jim Carroll wrote:
>> After experimenting, I can confirm this is the same issue we're seeing,
>> although experiencing it very differently from the MIT/Kerberos team.
>>I can
>> confirm that right now PKCS7 sign/encrypt/decrypt is broken.
>
>A fix is currently being reviewed. It includes a test. It just happense
>that
>the standard CMS/PKCS#7 tests use a very short content length. If it is a
>little longer they trigger the bug.

I don’t think I’ve seen any mentioning of this bug being addressed yet
(could’ve missed the notification, of course).

So what’s the status if this issue? Has the fix been reviewed and applied?

Thanks!
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5227 bytes
Desc: not available
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20160804/e0ba443a/attachment.bin>


More information about the openssl-dev mailing list