Skip to content

Signature verification broken #7

@infraweavers

Description

@infraweavers

Hiya,

I think this implementation's signature verification is different from both
https://github.com/jedisct1/go-minisign and https://jedisct1.github.io/minisign/

The attached file has a valid signature (also attached) as produced by https://github.com/jedisct1/minisign/releases/download/0.9/minisign-win32.zip :

D:\sign>"C:\Users\RobertEmery\Documents\minisign.exe" -V -m robtest.ps1 -P "RWQ3ly9IPenQ6Wgt/VYzMCdGdVJPPoNSyT+rtTddvqBgANTYdboko0zu"
Signature and comment signature verified
Trusted comment: timestamp:1617721023   file:robtest.ps1

Yet when run through this reimplementation it shows as invalid:

D:\sign>C:\Users\RobertEmery\Downloads\minisign-main\minisign-main\minisign.exe -V -m robtest.ps1 -P "RWQ3ly9IPenQ6Wgt/VYzMCdGdVJPPoNSyT+rtTddvqBgANTYdboko0zu"
Error: signature verification failed

ExampleValidSignature.zip

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions