* Victor Duchovni wrote on Fri, Feb 12, 2010 at 14:20 -0500:
> The limit is not (only?) an X.509 limit, rather the SSL/TLS
> record layer cannot carry messages larger than 2^14 bytes (plus
> some overhead for compression algorithms which provably need to
> be able to make some records larger in order to make most
> records smaller). Given that the server certificate message in
> the SSL handshake needs to fit into a single record, the
> SSL/TLS protocol constrains certificates to 2^14 (16K) bytes.

oki, thank you for the clarification.

  (So DER encoding is used, and it is allowing 128 byte long
  length fields allowing 2^1024 [a number taking four and a half
  line in xterm because 309 decimal digits long] bytes long value
  fields sufficient to enumerate every atom in the visible
  universe an unbelievable huge number of times
  - but in the end for certificates limit of 16384 [5 digit
  number] is in effect :-))

oki,

Steffen

 
About Ingenico: Ingenico is a leading provider of payment solutions, with over 
15 million terminals deployed in more than 125 countries. Its 2,850 employees 
worldwide support retailers, banks and service providers to optimize and secure 
their electronic payments solutions, develop their offer of services and 
increase their point of sales revenue. More information on 
http://www.ingenico.com/.
 This message may contain confidential and/or privileged information. If you 
are not the addressee or authorized to receive this for the addressee, you must 
not use, copy, disclose or take any action based on this message or any 
information herein. If you have received this message in error, please advise 
the sender immediately by reply e-mail and delete this message. Thank you for 
your cooperation.
 P Please consider the environment before printing this e-mail
 
 
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to