Dr Stephen Henson wrote:
> Anyway to answer the original question I believe you should hash
> public_key->length bytes of public_key->data.

  Thanks! Now there's just the problem of the cRLNumber extension, for
which I'll need to 'wrap' an ASN1_INTEGER in an ASN1_OCTET_STRING,
somehow. I've looked at your ca-fix source and I'm hoping that should
help me solve it.

> Having said that I haven't seen any CRLs that include this extension
> and almost nothing currently uses it.

  It was there in the PKIX draft, so I thought I'd better include it.
Besides, I'm unable to sign the CRL with the proper issuer key, so I'll
be needing some method for identifying the proper key to be used for
signature verification.
  Then I guess there are problems with getting these CRL's working with
OpenSSL. I've never actually been inside the X509_STORE's, X509_LOOKUP's
or the X509_LOOKUP_METHOD's...

  Thanks!

//oscar
begin:vcard 
n:Jacobsson;Oscar
tel;cell:+46 709 219507
tel;fax:+46 8 219505
tel;work:+46 8 208585
x-mozilla-html:FALSE
url:http://www.medcom.se
org:Media Communications Eur AB (publ)
adr:;;P.O. Box 1144;Stockholm;;S-111 81;Sweden
version:2.1
email;internet:[EMAIL PROTECTED]
title:Technical Consultant
fn:Oscar Jacobsson
end:vcard

Reply via email to