I have couple of questions  about X.509 v3 certificates in
general.

I have a system in which we were communicating keys using files/records.
I now want to migrate to certificates. There are fields in the record
which do not have a corresponding extension in X.509 spec. How can i
encode them in a certificate ? Is it possible at all to do so by having
user specified Extensions in the certificate ? If yes, then what are the
OIDs i can use and how to go about with the encoding ?

Can the Extended Key Usage field have user defined Key Purpose Ids ?

I will be having my own parser to parse the certificates but i would like
to be as close to the X.509 spec as possible.

Thanks,
- Pooja



______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to