Bug 483194 - Added verification data (CRL/OCSP) break integrity check
Summary: Added verification data (CRL/OCSP) break integrity check
Status: REPORTED
Alias: None
Product: okular
Classification: Applications
Component: general (show other bugs)
Version: 23.04.3
Platform: Fedora RPMs Linux
: NOR normal
Target Milestone: ---
Assignee: Okular developers
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-03-11 04:08 UTC by Matej Vašek
Modified: 2024-03-14 10:05 UTC (History)
1 user (show)

See Also:
Latest Commit:
Version Fixed In:


Attachments
Signed pdf with embedded OCSP response (49.50 KB, application/pdf)
2024-03-14 01:04 UTC, Matej Vašek
Details
Okular screenshot (54.88 KB, image/png)
2024-03-14 01:06 UTC, Matej Vašek
Details
Okular screenshot detail (54.12 KB, image/png)
2024-03-14 01:10 UTC, Matej Vašek
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Matej Vašek 2024-03-11 04:08:51 UTC
If verification information (CLR/OCSP) is added into a signed document okular wrongly claims "There have been changes since last signed". Including verification information CLR/OCSP should not affect integrity check.

STEPS TO REPRODUCE
1. Open signed document that also includes verification data (e.g. response from OCSP).

OBSERVED RESULT
Okular claims that document was changed since last signature was made.

EXPECTED RESULT
Signature is evaluated as up to date: i.e. the document has not been modified since signature was made.
Comment 1 Albert Astals Cid 2024-03-13 23:02:12 UTC
You will have to attach a document where this happens.
Comment 2 Matej Vašek 2024-03-14 01:04:18 UTC
Created attachment 167139 [details]
Signed pdf with embedded OCSP response
Comment 3 Matej Vašek 2024-03-14 01:06:08 UTC
Created attachment 167140 [details]
Okular screenshot
Comment 4 Matej Vašek 2024-03-14 01:07:16 UTC
(In reply to Albert Astals Cid from comment #1)
> You will have to attach a document where this happens.

I did attach such a pdf document and also include of screenshot of okular behaviour.
Comment 5 Matej Vašek 2024-03-14 01:10:28 UTC
Created attachment 167141 [details]
Okular screenshot detail
Comment 6 Matej Vašek 2024-03-14 01:20:48 UTC
The thing is that the only modification to the file was embedding OCSP response to it.
Comment 7 Matej Vašek 2024-03-14 01:25:13 UTC
Note that both Foxit Reader and Adobe Reader do not report any errors. Also some government pages seems to accept such a pdf.