support for PKCS7_NO_VERIFY in test_support.pkcs7_verify #12116
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR adds support for Pkcs7Flags::NOVERIFY so that we can verify pkcs7 signatures without verifying the certificates.
M2Crypto also exposes this option but I would prefer to use cryptography ;)
It is needed when the verifying a signed apple wallet pass. Now I can verify it with the call
without the NoVerify option I get the error:
The unittests as in
cryptography/tests/hazmat/primitives/test_pkcs7.py
Line 412 in 7a20576
use ECPrivateKey but when using RSAPrivateKey I get the above error.