2014 vs 2015 Direct Certificate Discovery Tool

36 views
Skip to first unread message

Joseph Shook

unread,
Aug 11, 2016, 6:23:42 PM8/11/16
to Direct Certificate Discovery Tool
I am testing .NET RI (base on, I also maintain the .NET RI) code against the 2014 tool and failing for the following

  • Processing Message(s):
    • Expected message digest value: 621516b0d0f93df6eda2e4eac72fac8faf2ff2d8d1057717a5641b1e3b13cbc5 does not match the calculated message digest: 207feb6c6e42b0359e0e76c55c7eadbdc8eb033bb90236abcd580f0cfd34ee79 (org.bouncycastle.cms.CMSSignerDigestMismatchException: message-digest attribute value does not match calculated value)
Yet I can run the same tests against the 2015 tool and pass.  This is the newest code with the HSM and single use cert support but the tests are using the typical single certificate as dual-use.  
Does the 2015 site test message digest?

The other difference from previous passing .NET versions is the upgrade from the 4.5 framework to the 4.6.1 framework.  I will continue to dig but any ideas are welcome.  

Thanks
Joe

sandeep...@gmail.com

unread,
Aug 12, 2016, 9:28:27 AM8/12/16
to Direct Certificate Discovery Tool
The 2015 DCDT does not check for message digest. The check was removed as part of the 2015 DCDT (v3.1) because of the move toward the use of single-use certificates (separate signing and encrypting certificates) instead of dual-use certificates (a certificate can be used for both signing and encrypting).


Thanks,

Sandeep

Joseph Shook

unread,
Aug 13, 2016, 8:55:19 AM8/13/16
to Direct Certificate Discovery Tool, sandeep...@gmail.com
Thank you for the reference.

Through further investigation I resolved the problem on on my end.   
Reply all
Reply to author
Forward
0 new messages