internal/der checks that bytes are one element of DER. internal/cms reads
the detached CMS signature of spec v0.11 29.10 and the RFC 3161 token of
29.11, in the order of the spec, with the closed table of algorithms (RSA
PKCS 1 and PSS of 2048 to 4096 bits, ECDSA on P-256, P-384 and P-521,
SHA-2), with the standard library only. A certificate is read with
encoding/asn1, so that a key of a curve Go lacks makes a signature "not
verifiable" and not malformed. internal/cms/cmstest builds them for tests.
Not wired into capsule yet.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>