#80: Re-introduce the issuer key hash into the Precertificate

Comment (by [email protected]):

 I don't understand this problem.

 The I-D says "SignedData.signerInfos MUST contain a signature from the
 same (root or intermediate) CA that will ultimately issue the
 certificate."

 signerInfos includes "SignerIdentifier ::= CHOICE {
         issuerAndSerialNumber IssuerAndSerialNumber,
         subjectKeyIdentifier [0] SubjectKeyIdentifier }"

 Surely this is sufficient to identify the issuer?

-- 
------------------------------+---------------------------------------
 Reporter:  [email protected]  |       Owner:  [email protected]
     Type:  defect            |      Status:  assigned
 Priority:  major             |   Milestone:
Component:  rfc6962-bis       |     Version:
 Severity:  -                 |  Resolution:
 Keywords:                    |
------------------------------+---------------------------------------

Ticket URL: <http://trac.tools.ietf.org/wg/trans/trac/ticket/80#comment:2>
trans <http://tools.ietf.org/trans/>

_______________________________________________
Trans mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/trans

Reply via email to