TO try and keep IE all nice and happy, I've included CRL URL's in
some certs I'm generating.  For fun (NOT!) I've used different
extensions in the CA cert and the "user" cert:

CA:
        X509v3 extensions:
            X509v3 CRL Distribution Points: 
                URI:http://www/myca.crl

User:
        X509v3 extensions:
            Netscape CA Revocation Url: 
                http://www/myca.pem

So what then is the problem ?

IE5 appears to insist on adding a number (01, etc) on the end of the
Netscape CA Revocation Url and if not present, reports an error about
not being able to verify the user because it can't get a CRL.

What's the deal here ?  Is IE5 using some secret version number thing
as an extension that I'm not aware of ?  Will all IE5's add the same
number on the end ?  Is using the "Netscape CA Revocation Url" in the
user section the source of this problem (Netscape people being weenies
of course ;) ?

Cheers,
Darren

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to