Samuel Liddicott wrote:
>
> A long long time ago I wrote a SSLeay cookbook for MSIE with Xenroll.dll
>
> Now I am active again and using my own cookbook!
>
> But the problem is that certificates, CA-signed and installed are marked in
> IE5 as fit for everything EXCEPT email and client-identification.
>
> They are marked for servers, code signing, encryped file systems, all kinds
> of stuff I have never heard of!
>
This is because IE5 by default assumes a CA certificate can be used for
anything. You can change this by using the extended key usage extension:
see the latest snapshot documentation for details.
> The only thing that has changed is the openssl.cnf file as I am using the
> default file + any changes I made to the ssleay.cnf file in the old days.
>
Hmmm thats odd. Try deleting+importing the CA again and see what usages
it gives.
If the CA certificate allows email/client but the imported cert does not
then something is amiss. I'm just not sure what yet :-)
Steve.
--
Dr Stephen N. Henson. http://www.drh-consultancy.demon.co.uk/
Personal Email: [EMAIL PROTECTED]
Senior crypto engineer, Celo Communications: http://www.celocom.com/
Core developer of the OpenSSL project: http://www.openssl.org/
Business Email: [EMAIL PROTECTED] PGP key: via homepage.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]