On Mon Jan 19 09:30:24 2015, [email protected] wrote: > > RFC 4055 as well as RFC 5754 do not make this difference, both say: > When any of these four object identifiers appears within an > AlgorithmIdentifier, the parameters MUST be NULL. Implementations > MUST accept the parameters being absent as well as present. > > If OpenSSL declines an empty paramter field then this is non-conformant > with theses RFCs. >
OpenSSL will tolerate both an absent parameter list and a NULL one. It did before this change and still does after it. This specific case rejects a certificate where the two AlgorithmIdentifier values in the certificate (signature and signatureAlgorithm) do not match. It seems odd that an implementation having decided it should represent an algorithm in one way for one field should then decide to represent an identical algorithm in a different way for another. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org _______________________________________________ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev
