Re: Critical certificate policies extension

Peter Gutmann <[email protected]> Thu, 21 Jul 2022 06:09:18 +0000
Newsgroups gmane.ietf.x509
Message-ID <SY4PR01MB6251EF2BC97B06A0DD673EF0EE919@SY4PR01MB6251.ausprd01.prod.outlook.com>
Niklas Matthies <[email protected]> writes:

>But you don't have different sets of applicable extension-specific
>requirements depending on whether the extension is critical or not.

It certainly doesn't seem to be correct behaviour.  When something like this
crops up in code, particularly when it's been implemented as a configurable
option, it's often because some large customer asked for it and it was made
configurable because everyone else doesn't want it that way... does the US
Federal PKI or other government PKI require this behaviour?

Peter.