This is to work around broken encodings and not just for OCSP. OpenSSL effectively uses the received encoding when computing signatures instead of converting it to DER. OpenSSL isn't alone in doing this and it is fairly common practice.
In the past several (rather important) certificates would have been unusable because they would technically have broken signatures if DER conversion had taken place. ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [EMAIL PROTECTED]
