LS,

I will post a request on this on the CABForum to see what they say about this. 
I know there is a F-t_F meeting upcoming in Oslo, maybe this can be on the 
agenda.

Kick

-------------------------------------------------------------------------------------
Kick Willemse
Product Manager
e-mail: [EMAIL PROTECTED]
weblog: http://www.papierloos.nl

DigiNotar B.V.
Vondellaan 8
1942LJ Beverwijk
telefoon: 0251-268888



-----Oorspronkelijk bericht-----
Van: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Namens Frank Hecker
Verzonden: dinsdag 29 april 2008 3:16
Aan: dev-tech-crypto@lists.mozilla.org
Onderwerp: Re: EV email usage

Eddy Nigg (StartCom Ltd.) wrote re email addresses in EV certificates:
> Can somebody else have also a look at this? In case the
> claims are correct and email address fields are allowed or required for
> EV SSL server certificates and *no* extended key usage is set *and*
> validation of the email address does not have to be performed, I suggest
> to take this to the CAB forum urgently!

I just looked at the latest EV guidelines, doing a search for various
email-related terms (e.g., "email", "e-mail", "RFC 822", "rfc822", etc.)
and also reading section C in detail. As far as I can tell, the
guidelines do not mention email addresses in any context relating to the
content of certificates. There certainly does *not* appear to be any
EV-related requirement that email addresses be included in EV certificates.

I also looked at real-life examples of EV certificates from several CAs.
None included an email address. Where present, the Certificate KeyUsage
extension had values of Signing and Key Encipherment, and the Extended
Key Usage extension had values of TLS Web Server Authentication and TLS
Web Client Authentication. (One certificate also included the Netscape
Certificate Type extension with values SSL Client Certificate
and SSL Server Certificate.)


Frank

--
Frank Hecker
[EMAIL PROTECTED]
_______________________________________________
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto
_______________________________________________
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to