RE: First submissions
"Jim Schaad (Exchange)" <[email protected]> Mon, 16 Aug 1999 16:25:48 -0700
| Newsgroups | gmane.ietf.smime-examples |
|---|---|
| Message-ID | <2FBF98FC7852CF11912A0000000000010ECB6115@DINO> |
> -----Original Message----- > From: Blake Ramsdell [mailto:[email protected]] > Sent: Monday, August 16, 1999 3:54 PM > To: 'Jim Schaad (Exchange)'; [email protected] > Subject: RE: First submissions > > > > -----Original Message----- > > From: Jim Schaad (Exchange) [mailto:[email protected]] > > Sent: Monday, August 16, 1999 3:39 PM > > To: [email protected] > > Subject: RE: First submissions > > > > 1. The CN should reflect the algorithm so we don't end up > > with cn=carl for > > both the RSA and DSS root certificates. > > Agree. Recommend that this be changed to CarlRSASelf and CarlDSSSelf. > > While we're on the subject, should the EE certificates have > the full name in > the CN also? For instance, cn=AliceRSASignByCarl (currently it is > cn=Alice). Yes -- I think that both the cn= and the email address in the subject-alt-name should also be changed. > > > 2. The Key Usage needs to include CRL issuence as well. > > Agree -- just so that we're on the same page, do you agree > that it currently > indicates that keyCertSign is asserted? Yes it currently is --- Certificate Signing (04) > > I will add cRLSign to the next version. > > Blake >