Kyle Hamilton wrote:

The problem is that the CA did not embed "00" before the serial number
of the certificate it signed -- and, by RFC, it is not required to.
RFC 3280 says:

4.1.2.2  Serial number

  The serial number MUST be a positive integer assigned by the CA to
  each certificate.  It MUST be unique for each certificate issued by a
  given CA (i.e., the issuer name and serial number identify a unique
  certificate).  CAs MUST force the serialNumber to be a non-negative
  integer.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to