top | item 45383114

(no title)

CBMPET2001 | 5 months ago

Ah, so the 'signed checksum' field isn't actually the checksum of the signed document? How odd . . . but yeah, now that I think about it, they couldn't know the hash of a document before they generate it, but they would need to in order to include it in the document, hence an impossible cycle; they must have overlooked that . . .

discuss

order

mjg59|5 months ago

Right, it's the hash of the document before they add the certificate page, but unfortunately there's no easy way to extract that to calculate it