> What is the behavior of openssl ca towards a field which is not listed > in the policy section? It will be ignored and quietly dropped. 'openssl ca' prints it out when displaying the request, but does not copy it into the issued certificate. Which also means that fields not specified in [policy] do not affect request validation in any way. Kaur ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]