Christian Huitema <huit...@huitema.net> writes:

>Receiver side: receive the message, parser with generic ASN.1 decoder,
>process the message using the "parsed" representation, re-encode with DER,
>check the signature.

Except that no true Scots... uhh, sane person ever even tried that.  I've
heard that there was one implementation, done in Europe, but have never seen
it.  Everyone else just treated what arrived as a blob and went with that.
That's why, years ago, on the PKIX list I said "there is only one encoding
rule and that is memcpy()".

>Well, we have learned a few things since 1994.

Except for the people who did secure XML, who not only ignored what we've
learned so far but made it worse by making it active content rather than flat
byte strings.

But that seems to be the rule for XML design in any case.

Peter.


_______________________________________________
TLS mailing list
TLS@ietf.org
https://www.ietf.org/mailman/listinfo/tls

Reply via email to