Re: [pkix] DER encoding in RFC 3161

"Todd E. Johnson" <tejohnson@yahoo.com> Thu, 30 July 2020 23:37 UTC

Return-Path: <tejohnson@yahoo.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 84BF43A126A for <pkix@ietfa.amsl.com>; Thu, 30 Jul 2020 16:37:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.452
X-Spam-Level:
X-Spam-Status: No, score=-1.452 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, REPTO_QUOTE_YAHOO=0.646, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=yahoo.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WIRGAZgYNzO3 for <pkix@ietfa.amsl.com>; Thu, 30 Jul 2020 16:37:18 -0700 (PDT)
Received: from sonic313-14.consmr.mail.bf2.yahoo.com (sonic313-14.consmr.mail.bf2.yahoo.com [74.6.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 844D63A126C for <pkix@ietf.org>; Thu, 30 Jul 2020 16:37:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1596152237; bh=XPOJG5LxGKwVeCHTYH1iIu+7EodFD47CMnj1uSWSW28=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=YLZizrEMSAA4HBh88EzZVIIQZ0J24i4YVEIeZ5eQiHRd5O2UbFi9aophqTJXnQimU+f+s1jk3i2Fq4fjuOtRHxjuKcqzAARzWNpHUAQGPke/82K8BTqlTFp3T32PdtXHZmuzAy2jsWCU8lireQ/TFa3c5PcOCw9ecLZJ/CgcTSFhLlrdjBkQBjzJKAZM6vAKd+hBb/rzbyqDQ7EkXf3xK/j7RIsWkd4eE0kbJDUtMkaRNX0xbzluSTqlNklo0UZhmnZVGCW+tRP7iAyEnJgN58yDY8MbZYnQWHhBvpVEgQDWM66a2GMAVI/fNGYAnncyuGdeNX0Fv7H27hZqAmyYYQ==
X-YMail-OSG: AEuz4DwVM1lvFSs5mw3YI2FlQD8FFGFNVHeA7FUTBgdSh0sBUi9G3QkVCizShST NYkParNqBA3a4wwspWY73c4vIZUnxSkMDcJNRZlRuHMZeYKJbTImDlyeh1tMzFpW2l.Z82d2OOXP mGvjncWjCPMXJwUypNeAogB3sPCoT9MduNl.h295xdVZvbgszvRV3NgaGt30K.LSPYd7FWyzKWnE WA7zbrW0Vm9vjvaH0Q7dmpzfezB6RTBniwnrydn63lwadbSB3JicveRHOdLkSJVfODj3ZzOf4.Gy UIOZNb4_dXm.RRzy3C2PoghXpu2rxljYwUaR_F17_Ab5MOgXPT.QlUs5pvGGqz7U_gcBhTclsfit KqnNmyDGW4X9Ef00u8_d8HC256MU8maOyMJh.kY8k0AL6Dfa4jp3exWv6pikSbwdV0u0T3lbr9b8 XlSMXz0YJfSTaIiS.TWI2fYThAZ_t5A43m7RI4cVcHiUKEwitiPQa4E3YGuSICN2qpDgoiCKXJuS 7cAtA8TbrDeASf5vW.woZ9g46TGk6dyZ1ogX_olWiucSvHQANsTo83rm1Tbxzarj0AcwJs6yo_1F EnTwD22Tsrb1pff5XXJc1CHzakxsswBq7djUyN2AlHbUWjhvqwWgQ0cNKNtCS.5iVQuFnPXIrdXL _42ZE34GqCG_XRDWy03HeuOroMwtQFcQU..HTMeIq5Gi_BiavKfz_o9heHzna677bsEg9Qcp2jso EQnqSVj5etDQTo8IQRkCDn8YDBtm0vLu.TEwGAfVICpQ5zISP1FVrXu5UEnJsWj94b3UJ2J7wzFm PUvaE6ppcdtVhKgBNvb4fDZ4HWCWI5.lbFkKjyMAM6ESLNJjskLv0i4bkVIc_y33gKJHQ7dZ9q80 L9CUDs_FG4dGvCZP7c9XFmeB67w_ju6stkmQlI_c81N8QBomS2Od6caaza.L5vw_o0yqbVfBZN.i JL9WHA.oqqlp01RqVrjXN_DE9.4CCt_Nvs.y0kA1eziWuGHyx9Lx85Ek7TPhMrhPdot5AALCv3Og ULz3agPe2Fil5vRdJoeZ.7AWnu1XdAeA3caXtwoQZjYnpsqRJKUjiNYzRnVeO8MJQrkwcyJ9rbDC nQYOPYmhxY_GDHhC3ovb9MiZ4xTsk.sPQjAwQeHiTOMxnkmbUBd1UdlPio5.IcWQ.eC9U53w.wk2 WCEj1hNGkJY6sANQxRW7HbWfRsGtQu6EXgFkr_gRIVlifgg2MZ672qQKoPSo3b2MzzXv4BwHbl6U scBvVhGBd7Z27XwMB9Po5e9Oe5fUXWkAATZmB4JNkz7FKqkUexYgENiaTgVJVf8tTyTSXq8RV2Ik hJoo0u8Azm7.sci1tomN1B7U7yNw.3cyfVUfvd2O3XIo5OJCyEqKW.Ay.FRE-
Received: from sonic.gate.mail.ne1.yahoo.com by sonic313.consmr.mail.bf2.yahoo.com with HTTP; Thu, 30 Jul 2020 23:37:17 +0000
Date: Thu, 30 Jul 2020 23:37:14 +0000
From: "Todd E. Johnson" <tejohnson@yahoo.com>
Reply-To: "tejohnson@yahoo.com" <tejohnson@yahoo.com>
To: "pgut001@cs.auckland.ac.nz" <pgut001@cs.auckland.ac.nz>, Phillip Hallam-Baker <phill@hallambaker.com>, Koichi Sugimoto <koichi.sugimoto=40globalsign.com@dmarc.ietf.org>
Cc: "pkix@ietf.org" <pkix@ietf.org>
Message-ID: <1927300389.6838404.1596152234095@mail.yahoo.com>
In-Reply-To: <1596104141331.18182@cs.auckland.ac.nz>
References: <PS1PR03MB48921EE23E93434559DF1ECE9D730@PS1PR03MB4892.apcprd03.prod.outlook.com> <CAMm+LwhdgfkbwXrfX8yiK3UDJRGOGzMJ2mXuyKqZWTdGbBE6gQ@mail.gmail.com> <1596104141331.18182@cs.auckland.ac.nz>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_6838402_923802203.1596152234092"
X-Mailer: WebService/1.1.16271 YahooMailAndroidMobile YMobile/1.0 (com.yahoo.mobile.client.android.mail/6.8.5; Android/10; QQ3A.200705.002; blueline; Google; Pixel 3; 5.19; 2028x1080; )
Archived-At: <https://mailarchive.ietf.org/arch/msg/pkix/uTmkHZrAKxS9F8TKwXU42k3RPC8>
Subject: Re: [pkix] DER encoding in RFC 3161
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Jul 2020 23:37:23 -0000

Peter,
 I received the exact same comment on our SCVP (5280) code. [What we should have done]

 
  On Thu, Jul 30, 2020 at 6:16, Peter Gutmann<pgut001@cs.auckland.ac.nz> wrote:   Phillip Hallam-Baker <phill@hallambaker.com> writes:

>It is sufficiently possible that there are ASN.1 parsers there that insist on
>strict DER with definite length encoding throughout

Highly unlikely, since too many things would break if you did this, the last
parser I know of that did this was in the mid-1990s.  The rule has always been
"take whatever blob the other side sends you and use that", thus my long ago
comment that "there is only one encoding rule and that is memcpy()".  So in
practice you don't need to worry about it.  I mean, in theory you should, but
in practice you don't.

Peter.

_______________________________________________
pkix mailing list
pkix@ietf.org
https://www.ietf.org/mailman/listinfo/pkix