Re: Updates prior to the release of cryptlib 3.3.4/3.4.0

Peter Gutmann <[email protected]>
Newsgroups gmane.comp.encryption.cryptlib
Message-ID <[email protected]>
"Peter Rybar" <[email protected]> writes:

>For the long-term validation it is strongly recommended to use
>expiredCertsOnCRL, ArchiveCutoff and OCSP positive statement as is defined in
>Common PKI Part 4: Operational Protocols and Common PKI Part 9: SigG-Profile
>as Common PKI Private OCSP - Extensions CertHash (Positive Statement).

Ugh, that's SigG stuff, I implemented a pile of that some years ago and as far
as I know no-one ever used it (backed up by the fact that it's been quietly
disabled in the last few releases without anyone noticing).  Can you provide a
convincing argument that it's worth supporting this when the other SigG stuff
was present for probably ten years or so without (AFAIK) anyone ever using it?

>> '216' isn't a cryptlib error code, they're all small negative integers.
>
>That is windows Runtime error 216 at 00403876  :o( if CL32.dll compiled with
>e.g. USE_CERTLEVEL_PKIX_FULL is used.

How are you getting this error?  That is, what do I need to do to reproduce
it?

>\cl32\cert\chk_use.c(272) : error C2065: 'KEYUSAGE_SIGN_GENERIC' : undeclared
>identifier

Just change KEYUSAGE_SIGN_GENERIC to KEYUSAGE_SIGN.

Peter.

_______________________________________________
Cryptlib mailing list
[email protected] via Mail: [email protected]
Archive: ftp://ftp.franken.de/pub/crypt/cryptlib/archives/
http://news.gmane.org/gmane.comp.encryption.cryptlib
Posts from non-subscribed addresses are blocked to prevent spam, please
subscribe in order to post messages.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.