[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Name constraints



"Housley, Russ" writes:
> Part of the slow implementation may be related to the fact that CAs are not 
> required to support name constraints.  I think that this is appropriate 

Curiously, the ca software I was using for this test is from one 
of those browser implementors.  Support decisions are
probably done on completely different bases!

> Son-of-2459 continues to include name constraints.    It says:
> 
>     At a minimum, applications conforming to this profile MUST recognize
>     4.2.1.7), basic constraints (section 4.2.1.10), name constraints
>     (section 4.2.1.11), policy constraints (section 4.2.1.12), extended

It does seem to be safe to say that at least some of the browser
revs can't meet this profile spec.