On 11/09/2015 23:26, Michael Heide wrote: > Various intermediate certs. Verisign, Symantec, etc. > But now I see, did't got it before: the root is always "Thawte Timestamping CA" -- using md5WithRSAEncryption. > > Example: > https://www.virustotal.com/en/file/1d1bb76575e780123814259eb2dbbf26f1c9035d8f0d4bab682703823b06323f/analysis/ Where can I see the actual file (Not the virustotal description of the signature), I would need to look at the actual details to make sense of this. By the way, whomever signed this seems to be mixing competing CAs (GlobalSign for the cert, Symantec for the timestamp). And this file is very new (July 2015), are you sure it uses the nonstandard EncryptedDigest calculation? Enjoy Jakob -- Jakob Bohm, CIO, Partner, WiseMo A/S. http://www.wisemo.com Transformervej 29, 2860 S?borg, Denmark. Direct +45 31 13 16 10 This public discussion message is non-binding and may contain errors. WiseMo - Remote Service Management for PCs, Phones and Embedded -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20150914/2214724a/attachment.html>