I thinkt that it is not a good idea to have files openssl.pod and
openssl.txt in the same directory: The names suggest that the latter
is a formatted version of the former, which is not true.

The X509v3 documentation in openssl.txt (which could get a different
filename) should mention that a basicConstraints pathlen is to be
interpreted different than OpenSSL's "verify_depth" stuff (the
pathLenConstraint counts just the CA path -- 0 means that a CA may
sign only end entities --, while verify_depth counts all certificates,
IIRC).
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to