[76770] in cryptography@c2.net mail archive
Re: It's a Presidential Mandate, Feds use it. How come you are not using FDE?
daemon@ATHENA.MIT.EDU (Peter Gutmann)
Sat Jan 20 13:54:59 2007
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: cryptography@metzdowd.com, Victor.Duchovni@MorganStanley.com
In-Reply-To: <20070119013923.GJ9170@piias899.ms.com>
Date: Sat, 20 Jan 2007 22:10:47 +1300
Victor Duchovni <Victor.Duchovni@MorganStanley.com> writes:
>It took reading the code to determine the following:
>
> - ASN.1 Strings extracted from X.509v3 certs are not validated for
> conformance with the declared character syntax. Strings of type
> PrintableString or IA5String may hold non-printable or non-ASCII
> data.
Just a word in OpenSSL's defence, see the X.509 Style Guide for the reasoning
behind this. I don't think any ASN.1-using security toolkit since TIPEM has
done character-set checking, it would fail to verify a large chunk of the
certs out there (I once had a TIPEM user complain to me that they had to stop
using it specifically because it would reject invalid character strings, which
encompassed a nontrivial portion of their user base).
Peter.
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com