[mpeg-OTspec] Re: factual error in the DSIG description in the OT spec.

Hin-Tak Leung htl10 at users.sourceforge.net
Wed Mar 30 03:28:25 CEST 2016


--------------------------------------------
On Tue, 29/3/16, Adam Twardoch (List) <list.adam at twardoch.com> wrote:

> I'd like to clarify
 that since 2005, FontLab Studio 5 has had an implementation
 of DSIG done using some opensource libraries, not using
 Microsoft's code. 
 
> Our
 implementation was not very thoroughly tested, though, and
 some users reported problems with it (it did break for some
 time in 2011-12 when we were porting the Mac version to
 Intel, but I believe it got fixed in 2014-15). I'm not
 sure how many fonts were signed with FLS5, but I do know
 that quite a few have. 
 
 Thanks for letting me know. Dalton Maag folks apparently also have a openssl + python + fonttools (?) based implementation of signing tool. Presumably you still check signatures through Microsoft's verification? For the purpose of this discussion, chktrust (part of MS font signing suite) and the 2003 font validator are the same thing, since checking in both cases are done by the same mssipotf.dll .

Would you corroborate my suggested spec correction outlined, based on experience with your implementation?

Hin-Tak



More information about the mpeg-otspec mailing list