What about saying each certificate SHOULD be a signer on *A* preceding certificate? This allows us to serve a single cert chain for both MD5 and SHA1, for example. (Contrived examples of course.)
_______________________________________________ Acme mailing list [email protected] https://www.ietf.org/mailman/listinfo/acme
