Dave, Responding to your question: > If that certificate has cA=false, and keyCertSign=0 and cRLSign=1, > isn't the subject of the certificate "a conforming CA"? No, it is an end entity. -- David Simonetti Securify (www.securify.com), 410-356-2260