Warwick,
today's random rumbling:
if a V3 certificate contains a DN (it has to, if it is to be looked up
in the directory), a DNS name, an EDI party name, and an rfc822 name,
what assertion does the signer of the certificate make about those
four names, or those four named objects?
That they are the same?
That the named entities all possess the same secret key, but the
relationship between them is otherwise unspecified?
That you must read the CA's policy document to find out what it asserts?
I *think* I like V3 certificates, with or without attachment to an
X.500 directory, but I'd like to know who gets to define semantics.
Harald A