Re: Clarification on "zero" hash value in SigPolicyHash (CAdES)

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Stefan Santesson <[email protected]> writes:

>To assign a specific meaning to one out of all possible but syntactically
>valid hash values, is exactly the type of specification work that leads to
>implementation errors and security vulnerabilities.

How would it lead to implementation errors and security vulns?  It's a value
that's guaranteed to not match anything while requiring zero changes to
existing code, what sort of implementation error would it lead to?

Peter.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.