Re: PKINIT with PA-PK-AS-REQ_OLD fails with ASN1_CHECK_TLEN:wrong tag

2017-02-02 Thread Jacques Henry
> > 1. The old draft9 support isn't intended to be used as a wrong-PIN > fallback; it is only there for interoperability with old PKINIT > implementations. It might be time to remove that support, since Windows > Server 2003 hit the end of its extended support life in 2015. > When talking to the

Re: PKINIT with PA-PK-AS-REQ_OLD fails with ASN1_CHECK_TLEN:wrong tag

2017-02-02 Thread Greg Hudson
On 02/02/2017 06:04 AM, Jacques Henry wrote: > When talking to the draft9 are you referring to this? > https://tools.ietf.org/html/draft-ietf-cat-kerberos-pk-init-09 Yes. Microsoft implemented this version of PKINIT and shipped it in Windows 2000, Windows XP, and Server 2003. Later versions of W