RE: First submissions

"Jim Schaad (Exchange)" <[email protected]> Mon, 16 Aug 1999 17:37:21 -0700
Newsgroups gmane.ietf.smime-examples
Message-ID <2FBF98FC7852CF11912A0000000000010ECB6116@DINO>
I would just as soon keep the certificates as clean as possible while still
matching the 2459 profile.

jim

-----Original Message-----
From: Dr Stephen Henson [mailto:[email protected]]
Sent: Monday, August 16, 1999 5:21 PM
To: [email protected]
Subject: Re: First submissions


Jim Schaad (Exchange) wrote:
> 
> I really think that there are two things I would like to change about
Carl's
> certificate.
> 
> 1.  The CN should reflect the algorithm so we don't end up with cn=carl
for
> both the RSA and DSS root certificates.
> 2.  The Key Usage needs to include CRL issuence as well.
> 

Yes I'd agree with that. 

What are the thoughts about having E-mail protection in extended key
usage for the end user certificate examples?

Steve.

-- 
Dr Stephen N. Henson.   http://www.drh-consultancy.demon.co.uk/
Personal Email: [email protected] 
Senior crypto engineer, Celo Communications: http://www.celocom.com/
Core developer of the   OpenSSL project: http://www.openssl.org/
Business Email: [email protected] PGP key: via homepage.