Root certificate bad signature - bug?

Werner Koch wk at gnupg.org
Mon Nov 19 20:10:15 CET 2007


On Mon, 19 Nov 2007 08:54, michal at prihoda.net said:

> I would really appreciate if anyone could look into it and will  
> gladly help in any way possible. The certificate is available at  
> http://www.acaeid.cz/root/rca.pem. Thanks in advance for any response.

There are two problems: One is that gpgsm does not import a certifciate
if the trailing line feed after the "-----END CERTIFICATE----" is
missing.

The other is due to the certificate itself as you correcly identified.
That certificate uses a low public exponent of 3 which might trigger the
bug.  I need to debug that further.



Shalom-Salam,

   Werner


-- 
Die Gedanken sind frei.  Auschnahme regelt ein Bundeschgesetz.




More information about the Gnupg-devel mailing list