Re: DER encoding in RFC 3161
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Martin Rex <[email protected]> writes: >That installed base maps Certificate based on the certificate fingerprint. Why is this a problem? In order to make it "break horribly" you'd need to deliberately re-encode the malleable parts of the certificate in a different format. Given the very widespread use of hash fingerprints to uniquely identify data items I think people know how to work with them by now, the rule being "don't gratuitously change the data being identified by the hash value". Peter.