Name Constraints, was Re: [caops-wg] Re: ca signing policy file

Mike Helm helm at fionn.es.net
Tue Oct 11 13:10:47 CDT 2005


David Chadwick writes:
> Now if you are telling me that most commercial CAs do not support name 
> constraints, that would be a powerful argument to support reverting name 
> constraints back to their original semantics.

As interesting as the name constraints tangent is, did it actually
address your question?

I assumed when you said "commercial CA" you meant something like
Verisign or Global sign &c.

But you could have meant a PKI environment like Entrust or Windows....





More information about the caops-wg mailing list