Replies: 2 comments 2 replies
-
As additional data point, here is what happens if you create two v6 signatures:
Note how the OPS + Sig pairs do not bracket the literal data packet: It is |
Beta Was this translation helpful? Give feedback.
-
Thanks for the report, I'll move this to a discussion since the crypto-refresh support is under development and unreleased. |
Beta Was this translation helpful? Give feedback.
-
OpenPGP.js messes up the salt when inline-signing (OPS vs Signature salt mismatch), yet OpenPGP.js (and PGPy) can still verify the signature:
https://tests.sequoia-pgp.org/v6.html#Inline_Sign_with_minimal_key_from_RFC9760_and_key__Alice___verify_with_key_from_RFC9760
And OpenPGP.js messes up the v4 signature: https://tests.sequoia-pgp.org/v6.html#Inline_Sign_with_minimal_key_from_RFC9760_and_key__Alice___verify_with_key__Alice_
Beta Was this translation helpful? Give feedback.
All reactions