W3C home > Mailing lists > Public > public-appformats@w3.org > April 2008

Re: [widgets-digsig] Comment on use of X.509 v3

From: Marcos Caceres <marcosscaceres@gmail.com>
Date: Thu, 3 Apr 2008 10:03:49 +1000
Message-ID: <b21a10670804021703v7a072abbje91845990dc1b57@mail.gmail.com>
To: "Hal Lockhart" <hlockhar@bea.com>
Cc: olli.immonen@nokia.com, public-appformats@w3.org, member-xmlsec-maintwg-request@w3.org

>  Since this is not well understood and the document is not generally
>  accessible, you might want to repeat the above in your document. In
>  fact, I would suggest changing it to say:
>
>  Implementations MUST be prepared to accept any version certificate.

The spec now reads:
"Implementations must be prepared to accept all X.509 certificates
versions identified in [X509v3] via the version field. To be clear,
the value of the version field identifies the version of an X.509
certificate in the following way:
  0 is X.509 version 1,
  1 is X.509 version 2,
  2 is X.509 version 3,
  if the version field is omitted, then treat the certificate as X.509
version 1."

Please let me know if that is clear enough.

Kind regards,
Marcos

-- 
Marcos Caceres
http://datadriven.com.au
Received on Thursday, 3 April 2008 00:04:29 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Thursday, 3 April 2008 00:04:30 GMT