Hi, Here I got a problem.

I use Netscape signtool 1.3 for AIX43 to sign a jar file, and so I want to verify the jar with my program, with OpenSSL libraries used.

My problem is:

if I give no flag in the PKCS7_verify, I got "error:21075075:PKCS7 routines:PKCS7_verify:certificate verify error".

If I give PKCS7_NOCHAIN or PKCS7_NOVERIFY, the PKCS7_verify will be ok.

I have checked the OpenSSL source, it will set the X509_PURPOSE_SMIME_SIGN purpose, Anyone can help me to give a brief introduction about this flag, and any helps on my problems?

 

Thanks in advance, and any suggestions are appreciated

 

rtm



Do You Yahoo!?
"是IT精英吗?小试牛刀获时尚大奖!"

Reply via email to