Identification algorithm of bad signature when the signature with SHA256

It is more a bug than a feature.

We have a PDF file that can be signed using Adobe Reader.

If we sign using Adobe Reader 8, the hash algorithm is sha1. All right.
If we sign using Adobe Reader 9.3.2,and default hash algorithm is sha256.

Well, if analyze us the PKCS7 after having signed with version 9.3.2,and we found that in the signerInfo:
-If decrypt us the RSA signature, it contains a sha256 hash.
- but the signatureAlgorithm value is ' 1 2 840 113549 1 1 5'. This means pkcs1-sha1WithRsaSignature.

The value of the content.signerInfos [0] .signatureAlgorithm field must be rsaEncryption or sha256WithRSAEncryption.
But do not sha1WithRsaSignature.

Do you know if this will be fixed in a newer version?

Hello

First place, Bravo to you to find it. Not there is that a lot of people in the world who can dig into that at this level, and I'm impressed that you found this.

Now to the meat and potatoes. I bet you use a digital ID to sign up with what happens in the Windows certificate store. Acrobat (and when I say Acrobat I mean really both Acrobat and Reader) has access to two built in signature management. We're compatible PPKMS MS-CAPI Manager (as Acrobat is a consistent application of CAPITAL) and the other is the local Manager of PPKLite. If the digital ID chose to sign with is in the Windows then Acrobat default certificate store using the CAPI compatible PPKMS Manager and let the Windows encryption package to do all the work. It is PPKMS (or more precisely, our friends in Redmond) as the return of the incorrect SignatureAlgorithmIdentifier. All we do is write the PKCS7/CMS object with the data returned by Windows, if we let the PPKMS do the work.

If you were to sign with a digital ID which is located in a P12 or PFX and not a digital ID in Windows, then Manager of signature of Adobe PPKLite would do the job and you will see the value of equal to 1.2.840.113549.1.1.1 SignatureAlgorithmIdentifier rsaEncryption.

There is a case to be made that the SignatureAlgorithmIdentifier value must be a compound algorithm where it includes the collection and encryption methods, but this isn't a requirement. When Acrobat is the validation of the signature is the DigestAlgorithmIdentifier to recalculate the hash and analysis in fact the SignatureAlgorithmIdentifier keep the part EncryptionAlgorithmIdentifier and launch the part of digest method.

The key is, it is a bug of Microsoft, and Yes, I have already told them.

Steve

Tags: Acrobat

Similar Questions

  • Is there a work around to show the Site identity button when the integration with facebook like/send etc. It disappears when it comes to the page, it's because of the iframe can be done if anything.

    Is there a work around to show the Site identity button when the integration with facebook like/send etc. It disappears when it comes to the page, it's because of the iframe

    What can be done if anything.

    Pages that use "mixed content" (parts of the use of the HTTP page and some use HTTPS) are not secure against tampering, they will not display the site identity button. To resolve this problem, make sure that external resources you are incorporation are available over HTTPS and you use HTTPS to nest them.

    For example, to iframe widgets like the Facebook 'Like' buttons, make sure that your iframe use src = "https://192.168.1.20 /...". »

    See also discussion here: http://stackoverflow.com/questions/3587021/facebook-like-button-breaks-https-ssl

  • BlackBerry Smartphones BlackBerry keeps beeping all the time - just beeps when the connection with the carrier is active.

    Gentlemen.

    I have a Curve 8900 with the 4.6.1.133 (Platform 4.2.0.85).

    This unit maintains a beep every 10 seconds, I tried to remove the battery when the BB was on, wait a minute, put it again.

    I looked at all the configurations.

    I Don t no the slightest idea and wanted to throw it in the window.

    Any ideas? Advice?

    NEW INFORMATION. The device stores only beep if the wireless connection with the carrier is active. If it s off the beeps stops. I m using Claro to the Brazil.

    Camilo

    I found the solution. This is a bug beetween the network operator's SIM card software and the BlackBerry device. It s already solved. I had to follow certain steps to enable and disable a specific feature of the network operator and wait a dialog box confirm my operation.

    The beeps comes with the dialog box, but the apears only dialog box if you are in a specific screen of the blackberry. If you are in the home screen, it will not appear and you hear the beep.

    Camilo

  • Data merge problem - bad values when exporting PDF with "All folders" only

    Hi - I have the weirdest problem with InDesign: I use merge data from .csv to create a deck of cards (9 per page), and when I export to PDF from the data merge Panel, one of my field has erroneous data: it uses values from previous records and which repeat.

    What is strange, is that when the noticed, all right. Is also very good if I create a merged Document and PDF export. Is also very good if I export to PDF using just the range of entries it is play: I don't get that wrong data if export as PDF, "All records" in the data merge Panel.  Very frustrating!

    Someone saw? I feel that my data is ok, if the export of individual records is very well...

    Cheers for any help.

    Thank you! Which has me on the path to what looks like a fix...

    Copy all the fields in a new file does not solve the problem - the same behavior, but after the start of charges, I started to adjust the sizes of the fields and stumbled upon a possible solution.

    A field that trouble is a text box for a single digit, if limits are quite small. The name of the field for example placeholder. > is bigger and complained of cut-off text.  Increase the limits of the text box to be at least the size of the reliable placeholder text solves the problem. It decreases the size of a single digit... back of the problem.

    How weird.

    Thanks Peter.

  • How to get to 'leave the event' script to run again when the form with the data file is reopened?

    I've created an Adobe Dynamic XML using LiveCycle Designer form with many fields / subforms that are 'visible' or the 'hidden' according to the selected options of different menu drop-down lists. Also, the form has been activated to save. Users can successfully fill out the form and save a copy with the data that has been entered.

    The problem I have is that when the recorded file is opened again in the 'hidden' fields / subforms that were previously made visible by selecting the appropriate options in the drop-down list NOT displayed now. However if you make the same selections from each of the drop-down list shows still hidden ONCE the fields / subforms are displayed, and do not contain data that has been entered.

    The problem seems to be that the script that determines whether a field / subform is 'hidden' or 'visible' is a

    "<event activity="output" name="event__exit">" "

    that is followed by

    If (this.rawValue is '0')- (i.e. the value of the drop-down list)

    sfCompanyDetails.presence = "visible";

    sfRecruitmentAgency.presence = 'hidden ';

    etc, etc.

    and, therefore, it is not executed again when the file is reopened.

    Can someone advise please how do I do this?

    Hello

    Check if you enabled the "auto" option to keep the script changes in the properties of the form.

  • error bad image when the awakening as well as in e-mails

    I use ie 9 and when I put computer to fall asleep and wake up then I find a picture of error hpqtra.exe - bad CFGMGR.32.dll C:\windows\system32\ then when I use windows mail and go to open some emails that I get mail of ein exe bad image

    Hello

    1. you use Internet explorer to access the windows messaging?
    2. you use Windows mail or Windows Live mail?
    3. don't you make changes on the computer before the show?

    Method 1:
    You can solve the problem of mail for windows with the help of the link:
    Solve problems with Windows Mail
    http://Windows.Microsoft.com/en-us/Windows-Vista/troubleshoot-problems-with-Windows-Mail


    Method 2:
    You can also try the following steps and check if the error occurs.
    a. Click Start, type C:\Windows\system32\cfgmgr32.dll.
    b. the file should appear in the menu.
    c. right click, try to choose "restore the previous version.

    Method 3:
    You can also perform a SFC scan and check if the problem occurs.
    Auditor of file system (CFS) scan to fix all of the corrupted system files. To do this, follow the steps mentioned in the link:
    How to use the System File Checker tool to fix the system files missing or corrupted on Windows Vista or Windows 7
    http://support.Microsoft.com/kb/929833

    If you use Windows live mail, then you can ask your question in the Pack Windows Live mail community forums link provided below for assistance.
    http://windowslivehelp.com/product.aspx?ProductID=15&WA=wsignin1.0
     
  • Why is my bad color when the cartridge is three quarters full?

    Hello

    I have a HP all in one C5880.  My color cartridge is three quarters full, but the color or terrible.  I can't use for greeting cards.  I have for years and this is the first time, the color was so BAD, I can't use my printer.

    Is there something I can do?

    Thank you very much for your answer.

    I learned from another forum that might help remove the cartridge, place it on a wet napkin for five to ten minutes.  I did it and the color has improved by about 75%.

    The Red is still not perfect, so I'll check what you have suggested.

    I called HP and they told me that I needed a new printer because the printer head or something was not working.

    Apparently, this is the cartridge that might have gotten hardened.  Happy that I do not buy another printer!

  • Bad audio when the DVD player works

    I have an Inspiron 1520.  For years, that everything worked well.  Now, I'm having a problem with my audio.  It works fine when I play music or movies from files on your computer.  But when I play something of my DVD (audio CD or DVD) drive, the sound is very crackley and stuttering.  It also occurs if the DVD player works (i.e. burn a disc) and I play a file (movie or music) from my computer.  There must be some sort of link between what is happening when my DVD drive is rotating & my speakers or other audio link.

    Any help would be greatly appreciated!

    Try this. Go to http://winhlp.com/node/10 they have a small script program to restore the DMA mode. Click on the link in their 1st step. (Note: for best results, use Internet Explorer when you run the script vbs to step 1). Read the instructions in steps 2 through 5, and then run the program. He made changes to your Windows registry database to try to give (s) the use of the DMA mode. If you want to know exactly what the program does, scroll to "Reactivate the DMA using the registry editor" for the full explanation.

  • Identification code Adobe has expired when the publication to BusinessCatalyst

    Amy ideas on his set?

    Hello

    In Adobe Muse, go to the Help menu-> log out

    Restart the Muse

    Republish. This should solve the problem

    Let me know if you have any question.

  • Siri &amp; command voice crazy when the execution with headphones

    Everyone knows a combination of Siri (and after I disabled Siri) then the voice command goes a bit out of whack? This happens when I'm out of the race, I have my iPhone 6plus in an armband and I use generally a few apps (Strava & MapMyRun) running and listening to music. I say try because recently Siri turned without my activation. I have disable Siri and then on another race and unusable voice control music playback. Effect, apart from the interruption of playback of music, had to skip songs, fast forward and usually impossible music.

    Initially I thought he could have my cuff by pressing the buttons somehow, but after a few tries I excluded only. I guess it must be something to do with the helmet, but does not know which affected them has an effect on this problem. They used to work properly.

    Thought I'd share a few comments. The fault was with the helmet. Must have been faulty wiring or a certain type of damage that has been feeding via the headphones and sending crazy Siri. A new pair of headphones did the trick, and once again I can listen to my music while on the race. I deliberately chose headset without a microphone this time. After all, I'm not really taking a call when I'm blowing and blowing on a race and I hope that can mean this pair last longer.

    Also, tip practice, might be useful to check the headphone jack for an accumulation of lint. I used a stick to fish out debris.

  • When the problems with flash will be in fire fox?

    100 times a day I have to click on the buttons to content flash is visible on Web pages

    due to this inconvenience, I started to look at other browsers, chrome allows for example to play flash without obctacles

    Hello, if you do want to allow flash manually all the time, then set it to always 'activate' in the firefox menu > addons > plugins.

    in which case it is blocked, because you are using a vulnerable version, then update the flash plugin if you are no longer exposed to exploits on each Web site you visit: https://www.mozilla.org/plugincheck/

  • Windows Explorer crashes when the click with the right button on folders

    My Windows Explorer crashes whenever I right click on a folder, any folder.  It is for me a "Windows Explorer has stopped working" then it gives me a warning 'Windows restarts.  Then he closes my Explorer window.  I tried many things to see if that would help and nothing has done so far.  Anyone has any suggestions on how to solve this problem or knows what could be the problem?

    Click right problems are very often caused by third-party programs adding entries in the context menu.  Here is a program that can help you manage these inscriptions: http://www.nirsoft.net/utils/shexview.html.  Here, another article written for XP, but it applies to Vista that may be useful: http://windowsxp.mvps.org/context_folders.htm.

    I hope this helps.

    Good luck! Lorien - a - MCSE/MCSA/network + / A +.

  • Should the Tomcat when the OPA with Siebel testing on dev local machine?

    Hello

    I'm seeing if I can install an environment of test-to-end on my dev machine. Basically, I want to write a few rules and trigger in Siebel on my machine before I push anything on the server. I know that the OPM has integrated Tomcat and I was wondering if I could use in a way that instead of installing a stand alone Tomcat on my PC.

    Anyone know if this is possible and what I need to configure to make it happen?

    Thank you
    CC

    Hi cc2.

    Short answer: No, tomcat is not necessary, any server or IIS for .NET, Java application will work

    Longer answer:

    Siebel and OPA communicate through Web Services and the OPA can be installed on a standard Java application server.

    The steps for Siebel and OPA working together are described in policy Oracle Automation Connector for Siebel Setup Guide, but basically, they work as follows.

    1. install the server of determinations and conclusions of Web on an application suiitable Server (any application server j2ee compatible should do).
    2. for determinations Server, make sure that you know what is the URL of the assessment exercise (tests it is strongly recommended).
    3 configure outbound web services in Siebel to appeal determinations Server.
    4 determinations of Web, to make Siebel Web Server Extensions installed and installed the OPA for Siebel connector. This creates the appropriate incoming Web services in Siebel.
    5. change the siebel-data - adapt .properties in determinations of the Web to the location of the incoming Web Services referred to in 4. (see above).

    Published by: frank.hampshire on October 17, 2011 16:23

  • Message when the project with external link display

    Dear Sir.

    I am very fimiliar with Robohelp 6 options. As I've updated from version 6 or 7, things were different. I have a huge project webhelp which consists of many subprojects, in most of them, there are hyperlinks to each other.
    the problem is that whenever I open a project that references an external subject, a message appears saying: (the hyperlink... used in... is outside the flow of the project and do not appear in the project manager)

    This is a standard message and if you like the links are good, there is an option to disable the warning.

    I suspect that you turned off in RH6 and installation for RH7 just brought.

  • When the clause with conditions

    Hi all

    I have a report that must be filtered according to user input in a field of text and drop-down list.
    The goal is to let the user enter either an exact value (based on the AutoComplete feature) or use the wildcard character %

    It is where comes the menu drop down. If they choose value1, AutoComplete, the exact value is used and the where clause would look like something below,
    select col1, col2, col3
    from table
    where :P1_FILTER in (select distinct col2 from another_table)
    If they choose value2, then where should deal with using the same function and % s. something like:
    select col1, col2, col3
    from table
    where :P1_FILTER like (select distinct col2 from another_table)
    How can I take care of this in 1 where clause? I'm kind of stuck trying to figure out.
    Thanks for any help.

    -Chris

    Try this:

    select col1, col2, col3
    from table
    where
    (
    :P1_FILTER in (select distinct col2 from another_table)
    AND
    :P1_LOV =1
    )
    OR
    (
     :P1_FILTER like (select distinct col2 from another_table)
    AND
    :P1_LOV =2
    )
    

    I hope this helps!
    Sam

Maybe you are looking for

  • No pictures

    I just down loaded Skype version 2.8.0.866. I contacted successfully a couple of friends and can hear each other, BUT there is no picture of me or my friends. The small blue video camera at the top of the screen is "grayed out". Can someone help me p

  • Name of the device changed but always communicate with the same device

    Hello! I have two 6501 NIDAQs that I use in two different test of PRINTED circuit board equipment. I gave them names 'Dev1' and 'Dev2.  For some reason they cannot not be plugged into the same computer at the same time (USB), given that my TestStand/

  • Setup of XP SP1 or SP1a (I guess it would be the network installer

    Where can I download the stand-alone installer for XP SP1 or SP1a? Please help, I'm going nuts! I have an installer of 2MB, but my Dell P4 retains heel "lose" the connection to the server even though I have DSL. I have saved since the SP2 and SP3 fil

  • Could not find 'newsgroups' option under the 'tools '.

    Research focus groups but can not find them. But open tools there is no element of discussion group proposed in the menu

  • BlackBerry smartphones remove cats from IM (gtalk)

    OK, so I installed gtalk and have been using it.  A question however, how to remove the old cats? I can develop and reduce to the minimum, but how to remove the "old"?