Re: AuthorityKeyIdentifier and SubjectKeyIdentifier in DRIP X.509 certs

Robert Moskowitz <[email protected]> Sun, 14 May 2023 19:46:09 -0400
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Peter,

Your comments cleared up for me the obvious place I was getting aKID 
from.  From the signing cert!

ARGH!!

All I had to do was backtrack and create my signing cert with the fix I 
had done for sKID and now I have the chain I am looking for.

Some times I get lost in the weeds.

Thanks

On 5/14/23 19:30, Peter Gutmann wrote:
> Robert Moskowitz <[email protected]> writes:
>
>> I SHOULD be able to use the DETS in keyIdentifier as I do with
>> SubjectKeyIdentifier, but openSSL is resisting my efforts.  So far.
> The aKID is copied from the issuing cert so I would imagine you can't just set
> it arbitrarily.  OTOH since the aKID is copied from the issuing cert the
> obvious way to get it into the subject cert would be to set it as the sKID in
> the issuing cert.
>
>> I was wondering if there is something I could do with authorityCertIssuer?
> Probably not for the same reason you can't set the aKID in the subject cert
> yourself.
>
> You then also run into the problem that the sKID/aKID is the universal
> identifier there and it's not clear what, if any, support there is for
> handling authorityCertIssuers.
>
> Peter.
>

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix