[openssl-dev] [EXTERNAL] Re: PKCS12 safecontents bag type deviation from spec

Blumenthal, Uri - 0553 - MITLL uri at ll.mit.edu
Tue Jan 16 23:32:46 UTC 2018


I think the change is justified.
—
Regards,
Uri

> On Jan 16, 2018, at 14:31, Sands, Daniel <dnsands at sandia.gov> wrote:
> 
> On Tue, 2018-01-16 at 14:50 +0000, Salz, Rich via openssl-dev wrote:
>> OpenSSL defines it as a SET OF and the spec says it’s a SEQUENCE
>> OF.  Ouch!  Will that cause interop problems if we change it?  (I
>> don’t remember the DER encoding rules)
>> 
>> 
>> 
> 
> Well, a SEQUENCE uses tag 16 while a SET uses tag 17, according to a
> quick reference I found.  So that could be an interoperability concern.
> But maybe this is the first actual use of nested safecontents, since
> this difference flew under the radar for so long :)
> -- 
> openssl-dev mailing list
> To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20180116/2ec75402/attachment.html>


More information about the openssl-dev mailing list