> Before signing, the encoder fills the field with a placeholder (0), repeated for the field's exact length - signs the entire payload including that placeholder, and then writes the real signature over the top of it. To verify, you put the placeholder back.
I hate shit like this. Do not let your crypto layer know about the structure of what it's signing. Keep security stupid.