Re: DER encoding in RFC 3161

"Manger, James" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <ME2PR01MB3011431F8DD66E5BC832A668E5450@ME2PR01MB3011.ausprd01.prod.outlook.com>
> since "certificate fingerprints" are pretty much the universal unique identifier for the things - fire up any cert viewer and you'll see them used, for example - I'd say that if there is something out there that rewrites certs and breaks the fingerprint then whatever it is is broken and needs to be fixed.
>
> More to the point, we've been using cert fingerprints for thirty-odd years without running into any problems, so if something turns up now that breaks them then that's the problem, not cert fingerprints.

Such whole-of-cert fingerprints are very widely used, but a slight change of context (from an allowlist to a blocklist) can make them unexpectedly dangerous.
Use whole-of-cert fingerprints in a blocklist ... then watch attackers sail through by tweaking a byte outside the toBeSigned portion.
 
--
James Manger
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.