[sidr] multi-value distinguished name question
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[sidr] multi-value distinguished name question
Tim Polk asked David Cooper (a NIST colleague) to check on the
question that was raised during our meeting yesterday morning. The
question was whether, if we require Subject and Issuer names in X.509
certs to be either just a CN or a CN plus a serialNumber (as a set),
one could use commonly available CA software generate certs. The
answer is that both OpenSSL and an NSS can do this. OpenSSL required
some configuration effort, but David provided the details of the
config params in his response!
I will check with someone who knows about OpenCA, to see what they say.
Steve
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.