On 3/5/03 1:31 PM, "Paul Hoffman / VPNC" <paul.hoffman@xxxxxxxx> wrote:There are other meanings than "I don't care". We need to be able to say "send me a cert of type other than 4", namely types 11, 12, and 13. Currently, we can't specify that.
It won't do that if we scope it correctly.
--Paul Hoffman, Director --VPN Consortium
Paul,
An empty CERTREQ still contains a cert type field. The issue being discussed is the semantics of a missing CA field (in other words the CA's DN), not a missing cert type.
While intended to allow for future expansion, the only form of certificate request currently defined is X.509 signing certificate (4).
--Paul Hoffman, Director --VPN Consortium