Re: Fwd: TLS/SSH bugs
Frederik Kriewitz <[email protected]> Tue, 9 Dec 2014 12:42:20 +0100
| Newsgroups | gmane.comp.encryption.cryptlib |
|---|---|
| Message-ID | <CAKCUjRUW77Bm-nK7WUZfU6zSs+fWXdKS-tT-d6zdQxNjYhWcmw@mail.gmail.com> |
On Thu, Dec 4, 2014 at 1:28 PM, Peter Gutmann <[email protected]> wrote: > Frederik Kriewitz <[email protected]> writes: >>Besides that there's an issue with spaces in the common name (I assume that's >>a problem caused by the APC engineers) and certificates using UTF8String data >>types (That might be a general problem). See >>http://forums.apc.com/message/65428#65428 > > That shouldn't be a cryptlib issue, it just takes whatever you feed it and, as > long as it's identifiable as a usable string type (latin-1, BMP, whatever) > it'll encode it as such. > >>Besides that I'm wondering if the SSL/TLS server implementation supports >>sending multiple certificates during the handshake (to support intermediate >>CAs). I briefly looked at the SSL/TLS server Session part of the manual and >>it only talks about a single certificate. > > cryptlib sends the entire cert chain, whatever it's given. The docs talk > about the server certificate, but if there's more there it'll send that as > well. Is there some kind of command line tool to create/convert/examine p15 containers? I would like to test an alternative tool (instead of the APC Security Wizard) to generate the file to track down these issues. See this post for an example what the Security Wizard does with ASN1 UTF8Strings: http://forums.apc.com/message/65550#65550 _______________________________________________ Cryptlib mailing list [email protected] via Mail: [email protected] Archive: ftp://ftp.franken.de/pub/crypt/cryptlib/archives/ http://news.gmane.org/gmane.comp.encryption.cryptlib Posts from non-subscribed addresses are blocked to prevent spam, please subscribe in order to post messages.