On Tue, 27 May 2008, Joerg Sonnenberger wrote:
Thanks for the details. Did I understand your answer right as "you must have NetBSD (for nbsvtool(1) - whatever that is) installed" to verify the binary pkg's signature? Can't this be done with openssl(1)?nbsvtool is the easiest way. The source of it also documents how it can be done directly with OpenSSL. Beside the way the digests are computed, it is using standard PKCS7.
On what list was all this discussed? - Hubert