Comment 54 for bug 1490804

Revision history for this message
Brant Knudson (blk-u) wrote : Re: PKI Token Revocation Bypass

Could we validate the fields that cms doesn't verify? For example, if the Object Identifier is always supposed to be `1 2 840 113549 1 7 1` then we reject any tokens that have a different value. Same for the padding.