Hi,

We're working on a firefox extension and want it code signed.  We
signed up for a Versign authenticode cert and following  this:
http://oyoy.eu/huh/firefox-extension-code-signed-with-spc-pvk/
we were fairly successful in building a signed extension.

It works great in firefox 3 but fails in firefox 2 with a -280 error.
Looking in the error log, there is the message:

Signature Verification Error: the signature on <foo> is invalid becase
the MANIFEST.MF file does not contain a valid hash of the file being
verified.

The file is one of our localization files and just as a test, we
removed the offending file, re-signed it and another locale file (not
in any particular order to the previous file location) with the same
error.

Any ideas what might be happening?  We've tried a lot of googling with
no success and we're running out of ideas.

Thanks in advance,
Will
_______________________________________________
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to