This is to work around broken encodings and not just for OCSP. OpenSSL
effectively uses the received encoding when computing signatures instead
of converting it to DER. OpenSSL isn't alone in doing this and it is
fairly common practice.

In the past several (rather important) certificates would have been
unusable because they would technically have broken signatures if DER
conversion had taken place.

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to