Maxime Dubois wrote:
> 
> What I wanted to know is: How does a root CA say it does not trust anymore
> a sub-CA it has signed before?

By revoking the certificate of the sub CA.
Revoking means putting it into the root CA's CRL.

Ciao, Michael.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to