What a shame... I thought it is simple...

So what parts of certificate are protected with signature?

Cly



                                                                                       
                                    
                    "Dale Peakall"                                                     
                                    
                    <dale.peakall@bit-art        To:     <[EMAIL PROTECTED]>   
                                    
                    s.com>                       cc:                                   
                                    
                    Sent by:                     Subject:     RE: netscape_comment 
extension                               
                    owner-openssl-users@o                                              
                                    
                    penssl.org                                                         
                                    
                                                                                       
                                    
                                                                                       
                                    
                    2001.02.14 17:40                                                   
                                    
                    Please respond to                                                  
                                    
                    openssl-users                                                      
                                    
                                                                                       
                                    
                                                                                       
                                    



> What do You think? May I use the netscape_comment extension to hold my
> application specific information in text form (maybe in base64)?

This is a non-authenticated attribute.  i.e. it's not signed and can be
changed by the user without changing the certificate signature.

So don't use it for anything related to security.

           - Dale.

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]




______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to