Samuel Liddicott wrote:
> 
> A long long time ago I wrote a SSLeay cookbook for MSIE with Xenroll.dll
> 
> Now I am active again and using my own cookbook!
> 
> But the problem is that certificates, CA-signed and installed are marked in
> IE5 as fit for everything EXCEPT email and client-identification.
> 
> They are marked for servers, code signing, encryped file systems, all kinds
> of stuff I have never heard of!
> 

This is because IE5 by default assumes a CA certificate can be used for
anything. You can change this by using the extended key usage extension:
see the latest snapshot documentation for details.

> The only thing that has changed is the openssl.cnf file as I am using the
> default file + any changes I made to the ssleay.cnf file in the old days.
> 

Hmmm thats odd. Try deleting+importing the CA again and see what usages
it gives.

If the CA certificate allows email/client but the imported cert does not
then something is amiss. I'm just not sure what yet :-)

Steve.
-- 
Dr Stephen N. Henson.   http://www.drh-consultancy.demon.co.uk/
Personal Email: [EMAIL PROTECTED] 
Senior crypto engineer, Celo Communications: http://www.celocom.com/
Core developer of the   OpenSSL project: http://www.openssl.org/
Business Email: [EMAIL PROTECTED] PGP key: via homepage.


______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to