Stephen Kent wrote:
The Netscape discussion for this extension makes little or no sense
to me, based on your description. As Frank notes, this is an
extension one expects to see in an EE cert, vs. a CA cert, so one
would not encounter multiple ones in validating a path. If I did use
this extension in a CA cert, given the semantics, it might well
conflict with an EE usage. Certainly the keyUasage bits for CA certs
and EE certs are distinct, so why would one expect a relationship of
the sort described for this extension.
Thank you Stephen for this clear comment.
I can now consider I have a definitive answer on that :-)
In fact, what Netscape describes is the behaviour of Microsoft products
today, not really it's own, as far as I understand.