Re: Updates prior to the release of cryptlib 3.3.4/3.4.0
Peter Gutmann <[email protected]>
| Newsgroups | gmane.comp.encryption.cryptlib |
|---|---|
| Message-ID | <[email protected]> |
"Peter Rybar" <[email protected]> writes: >For the long-term validation it is strongly recommended to use >expiredCertsOnCRL, ArchiveCutoff and OCSP positive statement as is defined in >Common PKI Part 4: Operational Protocols and Common PKI Part 9: SigG-Profile >as Common PKI Private OCSP - Extensions CertHash (Positive Statement). Ugh, that's SigG stuff, I implemented a pile of that some years ago and as far as I know no-one ever used it (backed up by the fact that it's been quietly disabled in the last few releases without anyone noticing). Can you provide a convincing argument that it's worth supporting this when the other SigG stuff was present for probably ten years or so without (AFAIK) anyone ever using it? >> '216' isn't a cryptlib error code, they're all small negative integers. > >That is windows Runtime error 216 at 00403876 :o( if CL32.dll compiled with >e.g. USE_CERTLEVEL_PKIX_FULL is used. How are you getting this error? That is, what do I need to do to reproduce it? >\cl32\cert\chk_use.c(272) : error C2065: 'KEYUSAGE_SIGN_GENERIC' : undeclared >identifier Just change KEYUSAGE_SIGN_GENERIC to KEYUSAGE_SIGN. Peter. _______________________________________________ Cryptlib mailing list [email protected] via Mail: [email protected] Archive: ftp://ftp.franken.de/pub/crypt/cryptlib/archives/ http://news.gmane.org/gmane.comp.encryption.cryptlib Posts from non-subscribed addresses are blocked to prevent spam, please subscribe in order to post messages.