PKCS #1 (June 3, 1991) says that md2 has the OIW-defined object
identifier { 1 3 14 7 2 2 1 }.
The TIS implementation, however, indicates that the RFC 1423
defined object identifier of RSA-MD2 is being used, which is
{ 1 2 840 113549 2 2 }.
PKCS #1 is wrong---it cited OIW agreements that were never adopted.
RFC 1319 defines the object identifier for RSA-MD2 as
1.2.840.113549.2.2.
We're aware of this problem, and we're in the process of updating PKCS
to reflect several similar registration problems. Sorry for the
inconvenience.
-- Burt Kaliski