Re: Globally Unique Serials in CA Chains

2009-02-02 Thread Brian A. Seklecki
grown up. -- C.S. Lewis l8* -lava (Brian A. Seklecki - Pittsburgh, PA, USA) http://www.spiritual-machines.org/ Show me a young conservative and I'll show you someone with no heart. Show me an old liberal and I'll show

Re: check_ssl_cert w/ PKI / X.509 Chain Validation

2008-08-06 Thread Brian A. Seklecki
to automate the extract process from. Anyway, the root CA DB doesn't change very often, so code can be written around this for now. ~BAS On Wed, 11 Apr 2007, Brian A. Seklecki wrote: These scripts are great thank you very much to all involved who contributed (no e-mail address for 'mastrboy

Globally Unique Serials in CA Chains

2008-03-05 Thread Brian A. Seklecki
Architecture question: Do certificate serial numbers within a multi-trier certificate authority chain need be globally unique? A Thunderbird user recently received the following error because his cert serial number, as signed by one CA, matched the serial number of the server, both of which

check_ssl_cert w/ PKI / X.509 Chain Validation

2007-04-11 Thread Brian A. Seklecki
/certdata.txt Thoughts? l8* -lava (Brian A. Seklecki - Pittsburgh, PA, USA) http://www.spiritual-machines.org/ __ OpenSSL Project http://www.openssl.org User Support Mailing List