Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Not enforcing DER encoding #153

Open
ydahhrk opened this issue Oct 29, 2024 · 0 comments
Open

Not enforcing DER encoding #153

ydahhrk opened this issue Oct 29, 2024 · 0 comments

Comments

@ydahhrk
Copy link
Member

ydahhrk commented Oct 29, 2024

Fort is parsing signed objects using a generic BER parser. (DER is a more strict version of BER.)

There used to be a check, but I deleted it during the 1.6.2 release review, because it was incorrect (and nontrivial to fix).

Though this is clearly RFC-mandated, I'm not aware of any vulnerabilities or meaningful misbehavior this violation might cause. I'll classify it as Medium for now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant