Hello,

If you have a signing hierarchy of A signs B, B signs C, and C signs D, so
that A is your root CA and D is the end user certificate.  If I want to
check that D is signed by A, does that mean that intermediate signers B and
C also have to be present in the certificate stack, or what openssl refer to
as the cert chain?

Would this be a hassle if you have a root CA with a lot of intermediate
signers?  That means that you have to store/locate all possible intermediate
signers to evaluate a couple of end user certificates.

Tat.





______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to