Am 19.01.2015 um 05:29 schrieb Uri Blumenthal via RT: > Well, technically youre correct - but from semantic point of view, > how different is an empty list, and a list presented as ASN.1 NULL? > Dont we have an empty list in both cases? And arent these two the > only two ways to represent an empty list (so theres little chance of > somebody utilizing this difference to craft an attack)?
It is the difference as of an empty tumbler on the table and no tumbler at all ;-) RFC 4055 as well as RFC 5754 do not make this difference, both say: When any of these four object identifiers appears within an AlgorithmIdentifier, the parameters MUST be NULL. Implementations MUST accept the parameters being absent as well as present. If OpenSSL declines an empty paramter field then this is non-conformant with theses RFCs. /Ann. _______________________________________________ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev
