Re: AuthorityKeyIdentifier and SubjectKeyIdentifier in DRIP X.509 certs
Robert Moskowitz <[email protected]> Sun, 14 May 2023 19:46:09 -0400
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Peter, Your comments cleared up for me the obvious place I was getting aKID from. From the signing cert! ARGH!! All I had to do was backtrack and create my signing cert with the fix I had done for sKID and now I have the chain I am looking for. Some times I get lost in the weeds. Thanks On 5/14/23 19:30, Peter Gutmann wrote: > Robert Moskowitz <[email protected]> writes: > >> I SHOULD be able to use the DETS in keyIdentifier as I do with >> SubjectKeyIdentifier, but openSSL is resisting my efforts. So far. > The aKID is copied from the issuing cert so I would imagine you can't just set > it arbitrarily. OTOH since the aKID is copied from the issuing cert the > obvious way to get it into the subject cert would be to set it as the sKID in > the issuing cert. > >> I was wondering if there is something I could do with authorityCertIssuer? > Probably not for the same reason you can't set the aKID in the subject cert > yourself. > > You then also run into the problem that the sKID/aKID is the universal > identifier there and it's not clear what, if any, support there is for > handling authorityCertIssuers. > > Peter. > _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix