Re: Signatures and encryption headers



Fabrice <fabrice.gautier@xxxxxxxxx> wrote:
But why? It seems that many application do it the other way around.

You can do it either way, but encrypting first, then mac'ing is
significantly easier to get right.

The easiest is of course to use a cryptographic mode with support for
integrity and clear-text headers. Those are quite easy to get right...

--
Kristian Gjøsteen
.