Re: [smime] Support for email address internationalization in RFC5280 certificates
George Michaelson <[email protected]> Wed, 6 Apr 2016 06:32:38 -0300
| Newsgroups | gmane.ietf.x509,gmane.ietf.smime |
|---|---|
| Message-ID | <CAKr6gn1Ou3cweepLVE7TgCH5F3fjA5Rrtfcr0Rq7tUoa9-ia4w@mail.gmail.com> |
Oh, if its not the *default* thats much better. I had assumed from how the problem presented this was because of default settings, but if we shot ourselves in the foot by selecting this mode, then there isn't an issue. Thanks for the clarification Stephen. -George On Tue, Apr 5, 2016 at 8:53 PM, Dr Stephen Henson <[email protected]> wrote: > On 05/04/2016 22:02, George Michaelson wrote: >> IIRC OpenSSL choses the most compact syntactically acceptable ASN.1 >> alphabet to represent strings. So, if your labels fit in IA5String, >> thats what it is. But if tomorrow you re-issue and they no longer fit, >> then it promotes to the next minimally correct ASN.1 alphabet. >> > > It can do that if it is configured to do so and the API is used with appropriate > flags. However that is not mandatory behaviour and if you don't want that you > don't have to use it. > > Steve. > -- > Dr Stephen N. Henson. > Core developer of the OpenSSL project: http://www.openssl.org/ > Freelance consultant see: http://www.drh-consultancy.co.uk/ > Email: [email protected], PGP key: via homepage. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix