(text deleted)
The digitalSignature bit is asserted when the subject public key is used for verifying digital signatures that are used with an entity authentication service, a data origin authentication service or/and an integrity service. Note that a certificate with only the digitalSignature bit set MUST NOT be used for verifying certificate or CRL signatures.
Sounds good to me.
Cool. Let's see what happens when Denis get back so,
This is fine with me. This solves the DS issue. We still need to solve the NR/CC bit issue. Denis
Stephen.