|
|
|
|
|
by briansmith
12 days ago
|
|
This is uninteresting. CAs are well aware that they have to encode the subject DN and issuer DN identically to maximize interoperability. There are several implementations that require that. If we were to make a new version of the spec for X.509 certificates, I would hope that we would eliminate all the non-UTF8 encodings so that this would be a non-issue. |
|
Differential parsing is a whole class of security bugs and they matter a lot. Take a look at HTTP Request Smuggling for examples.
Also, I am pretty sure there are more non-web x509 certificates out there than all the "browser trusted CAs" combined have signed. :)