[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
SubjectAltName verification
Hi all,
in RFC2459 (4.2.1.7) call :
>>Because the subject alternative name is considered to be definitively
bound to the publick key, all parts of the subject alternative name MUST be
verified by the CA.<<
What exactly this means?
Must be e.g. email unique in one CA? must be unique for one man?
If yes, is there any way to determine that this man has this email? (How
this problem is resolving for DNS, IP, URI, etc.?)
If no, someone can stand out for some else in email communication?
thanks for explanation
Martin