...
Let met ask this way: Suppose I receive a PEM/MIME signed message from
someone and they also include an application/key-data with a
<certchain>. (And suppose the sender has not included the optional
<crl> fields.) Where do I find the <keyid> for the issuers to request
the CRLs ? It is not in the <certchain>. Am I missing an interchange
that has to happen somewhere?
Two of the six name forms can be derived from a certificate directly
without the need for a keyid to make them unique. Both the
certificate's public key and its Issuer Name/Serial Number are easily
converted to IDs that can be used to retrieve a CRL without requiring
a keyid or any other information not contained in the certificate.
Mark
binOlgHwhockf.bin
Description: application/signature