Re: DER encoding in RFC 3161
"Manger, James" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <ME2PR01MB3011431F8DD66E5BC832A668E5450@ME2PR01MB3011.ausprd01.prod.outlook.com> |
> since "certificate fingerprints" are pretty much the universal unique identifier for the things - fire up any cert viewer and you'll see them used, for example - I'd say that if there is something out there that rewrites certs and breaks the fingerprint then whatever it is is broken and needs to be fixed. > > More to the point, we've been using cert fingerprints for thirty-odd years without running into any problems, so if something turns up now that breaks them then that's the problem, not cert fingerprints. Such whole-of-cert fingerprints are very widely used, but a slight change of context (from an allowlist to a blocklist) can make them unexpectedly dangerous. Use whole-of-cert fingerprints in a blocklist ... then watch attackers sail through by tweaking a byte outside the toBeSigned portion. -- James Manger