Richard Levitte - VMS Whacker wrote:
> 
> But I guess that the right way would be to make it less humanly
> readable and use the hash of the issuer DN, the same way it should be
> done according to RFC2560...

RFC2560:
"issuerNameHash is the hash of the Issuer's distinguished name. The
hash shall be calculated over the DER encoding of the issuer's name
field in the certificate being checked."

DER encodings of equivalent DNs are always the same? I don't think
so.

Ciao, Michael.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to