SMTP/TLS: MTA certificate type

Frederik Vermeulen <[email protected]> Thu, 24 Aug 2000 16:02:09 +0200 (METDST)
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
Hello,

since a typical MTA has both server and client capability, it
seems logical to me to have a single certificate with
X509v3_extensions mentioning both SSL server and SSL client
usage.

Apparently commercial CA's only deliver either server certificates or
client certificates however.

What are advantages/disadvantages of both schemes? Could the RFC
mention the combined usage possibility to convince CA's of the
need for server+client certificates?

Regards,

Frederik Vermeulen