ACTION-166: Warning on X509IssuerSerial

Suggested text for the end of section 4.4.4, after the new certificate
encoding language:

"Deployments that expect to make use of the X509IssuerSerial element should
be aware that many Certificate Authorities issue certificates with large,
random serial numbers. Such deployments should avoid schema-validating the
X509IssuerSerial element. XML Schema validators may not support decimal data
types with more than 18 decimal digits [XML-schema]."

I was considering that it might be useful to also include a sentence
indicating that a future version of the specification would correct this
problem, but don't know what people think about that.

-- Scott

Received on Sunday, 18 January 2009 23:19:53 UTC