Hacker News new | ask | show | jobs
by CBMPET2001 270 days ago
Ah, so the 'signed checksum' field isn't actually the checksum of the signed document? How odd . . . but yeah, now that I think about it, they couldn't know the hash of a document before they generate it, but they would need to in order to include it in the document, hence an impossible cycle; they must have overlooked that . . .
1 comments

Right, it's the hash of the document before they add the certificate page, but unfortunately there's no easy way to extract that to calculate it