RE: First submissions

"Jim Schaad (Exchange)" <[email protected]> Mon, 16 Aug 1999 16:25:48 -0700
Newsgroups gmane.ietf.smime-examples
Message-ID <2FBF98FC7852CF11912A0000000000010ECB6115@DINO>

> -----Original Message-----
> From: Blake Ramsdell [mailto:[email protected]]
> Sent: Monday, August 16, 1999 3:54 PM
> To: 'Jim Schaad (Exchange)'; [email protected]
> Subject: RE: First submissions
> 
> 
> > -----Original Message-----
> > From: Jim Schaad (Exchange) [mailto:[email protected]]
> > Sent: Monday, August 16, 1999 3:39 PM
> > To: [email protected]
> > Subject: RE: First submissions
> > 
> > 1.  The CN should reflect the algorithm so we don't end up 
> > with cn=carl for
> > both the RSA and DSS root certificates.
> 
> Agree.  Recommend that this be changed to CarlRSASelf and CarlDSSSelf.
> 
> While we're on the subject, should the EE certificates have 
> the full name in
> the CN also?  For instance, cn=AliceRSASignByCarl (currently it is
> cn=Alice).

Yes -- I think that both the cn= and the email address in the
subject-alt-name should also be changed.

> 
> > 2.  The Key Usage needs to include CRL issuence as well.
> 
> Agree -- just so that we're on the same page, do you agree 
> that it currently
> indicates that keyCertSign is asserted?

Yes it currently is --- Certificate Signing (04)
> 
> I will add cRLSign to the next version.
> 
> Blake
>