Microsoft Windows CryptoAPI fails to properly validate ECC certificate chains

Comment

From tptacek on HN:

If you can define your own curve parameters and get CryptoAPI to honor them, you can sign anything.

Read more