Hello, According to draft-guerrero-manet-saodv-00, in the signature for the extension, some fields of the extension itself are also signed. These normally include the Length of the extension. The Length of the extension is calculated as the size of the extension except the type and length fields. (according to the rfc) My question is simple: If the signature is variable in length and depends on the data, how can we sign over the length field of the extension which depends on the same signature we are producing? Depending on the algorithm being used, it can be impossible to predict a multiple of 4 bytes for the size of the signature. Should length be zeroed out for signature calculation? Thanks in advance, joao girao -- João Girão (Joao.Girao@ccrle.nec.de) NEC Europe Ltd., Network Laboratories Tel. (+49) 6221 90511-17 Fax: (+49) 6221 90511-55
Attachment:
signature.asc
Description: This is a digitally signed message part