11 Jun 2012 15:50
A different question on NC...
Miller, Timothy J. <tmiller <at> mitre.org>
2012-06-11 13:50:05 GMT
2012-06-11 13:50:05 GMT
Just to change a recent topic, if I wanted to completely prohibit a subordinate CA from issuing a particular name type (as opposed to restricting a name space), how would this be accomplished? IOW, if I wanted to restrict a sub-CA from issuing certificates containing any rfc822Name at all, what can I assert in the sub-CA cert? Would a critical NC with a null string in a permittedSubtrees base value work? Something else? Not possible under the spec? Enquiring minds want to know! :) Ignore implementations for the moment; theory only is fine for my current (nefarious?) purposes. -- T _______________________________________________ pkix mailing list pkix <at> ietf.org https://www.ietf.org/mailman/listinfo/pkix
RSS Feed