Re: [Openvpn-devel] [PATCH] revocation

2010-04-23 Thread Davide Brini
On Friday 23 Apr 2010 00:34:38 Peter Stuge wrote: > Davide Brini wrote: > > the serial number is just an (almost) arbitrarily large number. Why > > would a CA choose such a serial number? > > In order to avoid a chosen-prefix collision that works among other > things by predicting the serial numb

Re: [Openvpn-devel] [PATCH] revocation

2010-04-22 Thread Peter Stuge
Davide Brini wrote: > the serial number is just an (almost) arbitrarily large number. Why > would a CA choose such a serial number? In order to avoid a chosen-prefix collision that works among other things by predicting the serial number of certificates generated by the CA. http://www.win.tue.nl/